Topic module

Storage Account Security and Access

Storage access questions test firewalls, virtual network rules, SAS tokens, stored access policies, access keys, identity-based Azure Files access, and secure transfer.

Long-form learning
Concept to Risk to Memory to Check-up

How to study for AZ-104

Treat each AZ-104 item as an admin workflow: identify the scope, resource type, access boundary, deployment method, monitoring signal, or recovery requirement.

Core concepts

Concept 1

Storage Account Security and Access questions reward operational Azure administration judgment rather than simple service-name recall.

Exam cue: Identify the Azure scope: tenant, management group, subscription, resource group, resource, subnet, or identity.

Concept 2

The best answer identifies the scope, resource type, access path, deployment method, monitoring signal, and recovery requirement.

Exam cue: Match the tool to the administrative task: manage access, deploy, secure, monitor, back up, or troubleshoot.

Concept 3

Eliminate answers that confuse RBAC with policy, public access with private access, monitoring with backup, or templates with manual changes.

Exam cue: Prefer least privilege, repeatable deployment, protected storage, private networking, and validated recovery.

Risk pitfalls and guardrails

Using Azure Policy when the question asks who is allowed to perform an action.

Guardrail: Avoid answers that confuse RBAC with Policy, tags with network controls, dashboards with backup, or public exposure with secure private access.

Opening public access when private endpoints, service endpoints, or NSGs meet the requirement.

Guardrail: Avoid answers that confuse RBAC with Policy, tags with network controls, dashboards with backup, or public exposure with secure private access.

Assuming backup exists before checking vault, policy, retention, and restore validation.

Guardrail: Avoid answers that confuse RBAC with Policy, tags with network controls, dashboards with backup, or public exposure with secure private access.

Memory anchors

Storage Firewall

Storage firewalls restrict access to selected networks, IP ranges, or trusted services.

Virtual Network Rule

A virtual network rule limits storage access to selected subnets.

SAS Token

A shared access signature delegates limited storage access with defined permissions and time bounds.

Stored Access Policy

A stored access policy centralizes SAS constraints for supported storage resources.

Access Key

Storage account access keys grant broad account-level access and should be protected.

Azure Files Identity

Azure Files can use identity-based access for SMB file shares where configured.

Secure Transfer

Secure transfer requires encrypted requests to Azure Storage.

Private Endpoint

A private endpoint exposes storage privately through a virtual network.

Shared Key

Shared key authorization uses storage account keys and should be controlled carefully.

Access Review

Storage access should be reviewed for scope, duration, identity, and network boundary.

Checkpoint rule

Do the check-up only after you can summarize each concept in one sentence and identify one dangerous pitfall from memory.

Knowledge Check (after reading)

Short check-up to confirm understanding of this module.

Check-up Questions

1-2 question checkpoint

A storage account must accept requests only from two office public IP ranges and selected Azure subnets. Which setting should be configured?

A subnet needs to reach an Azure Storage public endpoint without using a private IP. The storage firewall should identify the subnet as trusted. What should be enabled?

Answer all questions to submit.

Next step personalized recommendations

What is Pass Harbor?

Completely free exam prep for 317 U.S. exams.

  • Practice questions
  • Flashcards
  • Study guides
  • Mock exams
  • No registration
  • No paywall
  • Start instantly
No more expensive exam prep. Quality study tools should be accessible to everyone.