A storage account contains 5,000 blobs accessed by many users. To ensure users can view only specific blobs based on blob index tags, what should you include in the solution?
Choose an answer
Tap an option to check your answer.
Correct answer: a role assignment condition.
Why this is the answer
A role assignment condition is the correct choice because it allows you to refine access to specific blobs based on their index tags. This feature integrates with Azure RBAC, enabling fine-grained, attribute-based access control. You can define conditions that grant access only if a blob's index tags match specified values, directly addressing the requirement to view only specific blobs based on blob index tags. A stored access policy defines permissions and an expiry for a SAS, but doesn't filter access based on blob index tags. Just-in-time (JIT) VM access is for securing administrative access to virtual machines, not for controlling access to storage blobs. A shared access signature (SAS) provides delegated access to resources, but without a role assignment condition, it doesn't inherently filter access based on blob index tags for multiple users dynamically.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed