You issued a user delegation SAS token for Azure Blob storage and it has been compromised. Which two actions can revoke or disable that SAS token? (Pick two.)
Choose an answer
Tap an option to check your answer.
Correct answer: Revoke the delegation key., Remove the role assignment for the security principal..
Why this is the answer
User delegation SAS tokens are signed with a user delegation key. Revoking this key immediately invalidates all associated user delegation SAS tokens, including the compromised one. This is a direct and effective method for revocation. Additionally, user delegation SAS tokens rely on the security principal's Azure RBAC permissions. Removing the role assignment for the security principal associated with the compromised SAS token will revoke its underlying permissions, thereby disabling the token's ability to access the resource. Deleting a stored access policy is not applicable to user delegation SAS tokens, as they are not associated with stored access policies. Regenerating the account key does not affect user delegation SAS tokens, as they are signed with the user delegation key, not the account key.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed