Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Microsoft AZ-500 Exam - Topic 3 Question 104 Discussion

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.You have an Azure subscription named Sub1.You have an Azure Storage account named sa1 in a resource group named RG1.Users and applications access the blob service and the file service in sa1 by using several shared access signatures (SASs) and stored access policies.You discover that unauthorized users accessed both the file service and the blob service.You need to revoke all access to sa1.Solution: You regenerate the Azure storage account access keys.Does this meet the goal?
A) Yes
B) No

Microsoft AZ-500 Exam - Topic 3 Question 104 Discussion

Actual exam question for Microsoft's AZ-500 exam
Question #: 104
Topic #: 3
[All AZ-500 Questions]

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.

You have an Azure subscription named Sub1.

You have an Azure Storage account named sa1 in a resource group named RG1.

Users and applications access the blob service and the file service in sa1 by using several shared access signatures (SASs) and stored access policies.

You discover that unauthorized users accessed both the file service and the blob service.

You need to revoke all access to sa1.

Solution: You regenerate the Azure storage account access keys.

Does this meet the goal?

Show Suggested Answer Hide Answer
Suggested Answer: A

Generating new storage account keys will invalidate all SAS's that were based on the previous keys.


Contribute your Thoughts:

0/2000 characters
Caitlin
4 days ago
Totally agree, that's the right move!
upvoted 0 times
...
William
10 days ago
Regenerating access keys will revoke all SAS tokens.
upvoted 0 times
...
Margurite
15 days ago
I feel like this is a trick question. Regenerating keys seems like a good step, but I wonder if it completely meets the goal of revoking all access.
upvoted 0 times
...
Theola
20 days ago
I’m a bit confused about this one. I know that regenerating keys affects SAS tokens, but what if there are other access methods in play?
upvoted 0 times
...
Lorean
25 days ago
I remember a practice question where we had to revoke access, and regenerating keys was mentioned as a solution. It seems like it should work, but I feel like there might be more to it.
upvoted 0 times
...
Charisse
2 months ago
I think regenerating the access keys would revoke the existing SAS tokens, but I'm not entirely sure if it covers all access methods.
upvoted 0 times
...

Save Cancel