You publish time-limited download links for blobs to external partners. You must be able to revoke any issued links immediately if needed. The storage account must use encryption with customer-managed keys stored in Azure Key Vault. Which two actions should you take?
Choose an answer
Tap an option to check your answer.
Correct answer: Issue service SAS tokens tied to a stored access policy on the container; revoke by deleting or updating the policy, Enable customer-managed keys for the storage account using a Key Vault key and grant the storage account access to the key.
Why this is the answer
To meet the requirement of immediately revoking time-limited download links, issuing service SAS tokens tied to a stored access policy on the container is crucial. Stored access policies provide a centralized control point, allowing you to revoke all associated SAS tokens by deleting or modifying the policy without waiting for individual token expiry. Account SAS tokens cannot be revoked before their expiry, and user delegation SAS relies on Azure AD token expiry, which doesn't offer immediate revocation for specific links. For customer-managed encryption keys, you must enable this feature on the storage account, linking it to a Key Vault key and granting the storage account appropriate access to that key. Keeping Microsoft-managed keys does not meet the customer-managed key requirement.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed