You must give the inventory service development team access to retail store location data. Which method should you use to grant that access?
Choose an answer
Tap an option to check your answer.
Correct answer: Shared access signature (SAS) token.
Why this is the answer
A Shared Access Signature (SAS) token is the correct method because it provides granular, time-limited, and specific access to Azure Storage resources, such as blobs containing retail store location data, without exposing account keys. This allows the inventory service development team to access only the necessary data for a defined period and with specific permissions (e.g., read-only). Azure RBAC roles are for managing access to Azure resources themselves (like the storage account), not individual objects within them. While an RBAC role could grant access to the storage account, it wouldn't be as granular or time-limited for specific data access as a SAS token. Azure AD access, ID, and refresh tokens are used for authenticating users or applications with Azure AD and granting access to protected APIs or resources, but they don't directly provide granular access to individual storage objects like a SAS token does.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed