Multiple applications currently use storage account access keys for blob access. You must rotate keys with zero downtime and begin moving apps to Azure AD–based authorization. What should you do?
Choose an answer
Tap an option to check your answer.
Correct answer: Store the key in Azure Key Vault, switch apps to use the secondary key, regenerate the primary key, update apps to use the new primary key, then regenerate the secondary key, Adopt user delegation SAS for blobs based on Azure AD and assign appropriate RBAC roles (for example, Storage Blob Data Contributor) to app identities.
Why this is the answer
The first correct option describes the standard, zero-downtime key rotation process. By switching to the secondary key, regenerating the primary, updating applications, and then regenerating the secondary, you ensure continuous access. The second correct option addresses the long-term goal of moving to Azure AD-based authorization. User delegation SAS tokens, combined with Azure AD and RBAC roles like Storage Blob Data Contributor, provide a more secure and manageable way to grant access to specific blobs without sharing account keys. Regenerating both keys simultaneously would cause downtime. Continuing with connection strings and enabling trusted services doesn't address key rotation or the move to Azure AD. The Reader role is insufficient for data access; a data-specific role like Storage Blob Data Reader or Contributor is needed.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed