A storage account named storage contains a blob of images. Client access is granted using shared access signatures (SAS). You need to ensure users receive a warning when they create a SAS that exceeds a seven-day validity period. What setting should you change on the storage account?
Choose an answer
Tap an option to check your answer.
Correct answer: Set Allow recommended upper limit for shared access signature (SAS) expiry interval to Enabled..
Why this is the answer
Setting "Allow recommended upper limit for shared access signature (SAS) expiry interval" to Enabled directly addresses the requirement by configuring the storage account to warn users when they attempt to create a SAS with a validity period longer than the recommended seven days. This feature is designed specifically for this purpose, enhancing security by preventing overly long-lived SAS tokens. Enabling a read-only lock would prevent modifications to the storage account itself, not warn about SAS expiry. Configuring an alert rule could monitor for SAS creation events, but it wouldn't inherently provide a warning during the creation process based on expiry. Adding a lifecycle management rule is for managing blob data based on age or access patterns, not for SAS expiry warnings.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed