AZ-500 exam dumps

AZ-500 practice question 155 of 273

Microsoft Azure Security Technologies. Associate level, Microsoft. Free question with the correct answer and a full explanation.

AZ-500 Question 155

Single answer

You are a security engineer for a manufacturing firm that wants to store sensitive data in Azure Files. Your IT environment includes Windows servers that are domain-joined to Azure AD Domain Services (Azure AD DS). You need to configure granular, user-level authentication for these domain-joined servers to access Azure Files. Which method should you choose to securely grant user-specific access to the Azure file share?

  1. A

    Use the storage account key to mount the file share on each Windows server

  2. B

    Provide Shared Access Signatures (SAS) for each user with least-privilege permissions

  3. C

    Configure Azure AD DS authentication for SMB access to Azure Files

  4. D

    Assign built-in Azure RBAC roles to control file share permissions at the directory level

Show answer and explanation

Correct answer: C

Explanation

To achieve user-level authentication and granular access control for Azure Files from Windows servers joined to Azure AD Domain Services, you should configure Azure AD DS authentication over SMB. This approach allows users to use their domain credentials and ensures role- and user-based access at the file and folder level. For reference, see Microsoft documentation on 'Enable and configure Azure AD Domain Services authentication for Azure Files SMB access': https://learn.microsoft.com/azure/storage/files/storage-files-active-directory-overview.

  • A. Incorrect.

    Option 1: Using the storage account key (primary or secondary) mounts the file share for all users on the server with the same privileges, making it impossible to differentiate user-level access. This conflicts with the requirement for granular, user-based authentication.

  • B. Incorrect.

    Option 2: While generating a Shared Access Signature (SAS) can limit permissions and access duration, SAS does not inherently integrate with user-level identity from Azure AD DS. It is typically not used for domain-based SMB access, and would require additional processes to manage keys per user.

  • C. Correct.

    Option 3: Configuring Azure AD DS authentication for SMB is the recommended way to allow users to use their domain credentials for access, thereby enabling granular control and seamless single sign-on through standard Windows file-sharing protocols. It aligns with the requirement for secure, user-level authentication.

  • D. Incorrect.

    Option 4: Although Azure RBAC roles can help control the overall access at an Azure storage level, they do not directly enforce SMB file-level permissions. RBAC alone does not provide detailed file and folder ACLs for user-level access on an SMB file share.

Timed practice exam

Take a AZ-500 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam