You plan to grant specific Azure AD user accounts read access to Azure Cosmos DB databases that use the SQL API. Which of the following should you use to provide that access?
Choose an answer
Tap an option to check your answer.
Correct answer: A resource token combined with an Azure role assignment (Access control/IAM).
Why this is the answer
A resource token combined with an Azure role assignment is the correct approach. Resource tokens provide granular access to specific Cosmos DB resources (databases, containers, documents) for a limited time, without exposing the master key. When combined with an Azure role assignment (Access control/IAM), you can assign roles to Azure AD user accounts, granting them permissions to generate or use these resource tokens, thereby controlling their read access to the SQL API databases. Shared Access Signatures (SAS) are primarily used for Azure Storage, not Cosmos DB. Certificates and Azure Key Vault are used for secure key management and authentication, but not directly for granting granular data access within Cosmos DB. Master keys provide full administrative access and should not be distributed to individual users for read-only access; Azure Information Protection policies are for data classification and protection, not access control within Cosmos DB.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed