exam questions

Exam AZ-305 All Questions

View all questions & answers for the AZ-305 exam

Exam AZ-305 topic 1 question 66 discussion

Actual exam question from Microsoft's AZ-305
Question #: 66
Topic #: 1
[All AZ-305 Questions]

HOTSPOT
-

You have an Azure subscription.

You plan to deploy five storage accounts that will store block blobs and five storage accounts that will host file shares. The file shares will be accessed by using the SMB protocol.

You need to recommend an access authorization solution for the storage accounts. The solution must meet the following requirements:

• Maximize security.
• Prevent the use of shared keys.
• Whenever possible, support time-limited access.

What should you include in the solution? To answer, select the appropriate options in the answer area.

NOTE: Each correct selection is worth one point.

Show Suggested Answer Hide Answer
Suggested Answer:

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
mykola_yakovliev
Highly Voted 1 year, 5 months ago
1. For the blobs - a user delegation SAS only To maximize security it's better to use a user delegation SAS: From docs: As a security best practice, we recommend that you use Azure AD credentials when possible, rather than the account key, which can be more easily compromised. When your application design requires shared access signatures, use Azure AD credentials to create a user delegation SAS to help ensure better security. This also prevents using shared keys & supports time-limited access. Note: user delegation SAS do not support stored access policies. 2. For the file shares - Azure AD credentials It fulfills the requirement to maximize security (the most secure way recommended by Microsoft), but doesn't support time-limited access, which is optional and has lower priority than security. Source: https://learn.microsoft.com/en-us/rest/api/storageservices/create-user-delegation-sas.
upvoted 50 times
tommylux
2 months, 2 weeks ago
I can't create a new comment, but to add, the question states "Prevent the use of shared keys" Correct answer is "A user delegation shared access signature (SAS)", given that a SAS is a secured against the private key and we want to avoid shared keys.
upvoted 1 times
...
...
23169fd
Highly Voted 8 months, 2 weeks ago
User Delegation SAS (for blobs): Security: User delegation SAS uses Azure AD credentials to generate the SAS token, providing a higher level of security. Time-limited access: SAS tokens can be configured with specific start and expiry times, supporting time-limited access. Azure AD Credentials (for file shares): Security: Azure AD provides secure authentication and authorization, eliminating the need for shared keys. Access Management: Azure AD allows fine-grained access control and integration with SMB protocol for file shares.
upvoted 5 times
...
[Removed]
Most Recent 3 months, 3 weeks ago
WRONG For the blobs: A user delegation shared access signature (SAS) only For the file shares: Azure AD credentials (Keyword: maximize security)
upvoted 3 times
...
Thanveer
3 months, 4 weeks ago
For the Blobs: c)A user delegation shared access signature (SAS) For the File Shares: a) Azure AD credentials
upvoted 2 times
Thanveer
3 months, 4 weeks ago
Correction: - For the Blobs: a)A user delegation shared access signature (SAS) For the File Shares: a) Azure AD credentials
upvoted 1 times
...
...
cosmicT73
4 months, 2 weeks ago
a user delegation SAS only Azure AD credentials https://learn.microsoft.com/en-us/rest/api/storageservices/create-user-delegation-sas
upvoted 1 times
...
Arthur_zw
5 months, 1 week ago
Stored access policies allow you to define a set of permissions on a container or blob that you can associate with a service-level SAS (signed with the storage account key), whereas a user delegation SAS is signed with EntraID credentials. So it should be SAS only for the 1st option
upvoted 2 times
...
salned
6 months, 1 week ago
I think the correct answer should be: - For the blobs: 'a user delegation SAS only' (more secure and granular access control) - For the file shares: 'Azure AD credentials' But who knows..
upvoted 2 times
...
rtsh06
9 months, 2 weeks ago
This question appeared in my exam on 13th May 2024. The given answer is correct.
upvoted 2 times
...
Lazylinux
10 months, 1 week ago
i agree with 1. A user delegation SAS only 2. Azure AD credentials
upvoted 2 times
...
varinder82
11 months, 2 weeks ago
Final Answer : 1. A user delegation SAS only 2. Azure AD credentials
upvoted 3 times
...
randy0077
1 year, 4 months ago
Answer: - user delegation SAS only - AzureAD authentication
upvoted 4 times
...
U4ea
1 year, 4 months ago
I'm not 100% sure on the correct answers but found the following info: "Stored access policies are not supported for the user delegation SAS or the account SAS." https://learn.microsoft.com/en-us/rest/api/storageservices/define-stored-access-policy So "user SAS + stored access policies" are wrong at least for both questions. File Share doesn't allow Azure AD (only AD DS like btboudreaux said) login so I guess it is regular user SAS for question2? It feels wrong though.
upvoted 2 times
ec2user
1 year, 4 months ago
A user delegation SAS is supported for Azure Blob Storage and Azure Data Lake Storage Gen2. Stored access policies are not supported for a user delegation SAS. https://learn.microsoft.com/en-us/rest/api/storageservices/create-user-delegation-sas so since user delegated SAS isn't supported for file share, the only answer left is Azure AD credentials for question 2 and has to be the answer(though incomplete) for this specific question.
upvoted 8 times
...
...
btboudreaux
1 year, 4 months ago
I'm confused about the File Shares part of the question. The question states that the File Shares will be accessed over SMB. According to this documentation, and testing, you cannot access File Shares via SMB by Azure AD alone. You need On Prem Synced accounts or Azure ADDS. https://learn.microsoft.com/en-us/azure/storage/files/storage-files-active-directory-overview
upvoted 3 times
chair123
12 months ago
That's interestingly true
upvoted 2 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago