exam questions

Exam AZ-304 All Questions

View all questions & answers for the AZ-304 exam

Exam AZ-304 topic 2 question 29 discussion

Actual exam question from Microsoft's AZ-304
Question #: 29
Topic #: 2
[All AZ-304 Questions]

You have an Azure Active Directory (Azure AD) tenant.
You plan to deploy Azure Cosmos DB databases that will use the SQL API.
You need to recommend a solution to provide specific Azure AD user accounts with read access to the Cosmos DB databases.
What should you include in the recommendation?

  • A. shared access signatures (SAS) and conditional access policies
  • B. certificates and Azure Key Vault
  • C. a resource token and an Access control (IAM) role assignment
  • D. master keys and Azure Information Protection policies
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
pattasana
Highly Voted 4 years, 6 months ago
Given answer is correct
upvoted 36 times
sanketshah
4 years, 5 months ago
given answer is correct.
upvoted 6 times
Examerr
3 years, 9 months ago
given answer is correct.
upvoted 3 times
...
...
...
azurecert2021
Highly Voted 4 years, 4 months ago
given answer is correct. You can use resource tokens to get access to the data in Azure Cosmos DB. And you can provide role-based access control to the users defined in Azure AD. Azure Cosmos DB uses two types of keys to authenticate users and provide access to its data and resources. Primary keys Used for administrative resources: database accounts, databases, users, and permissions Resource tokens Used for application resources: containers, documents, attachments, stored procedures, triggers, and UDFs. as here we read access to the Cosmos DB databases so we need use a hash resource token specifically constructed for the user, resource(database), and permission(read). assign Cosmos DB Account Reader Role to user through Access control (IAM) RBAC https://docs.microsoft.com/en-us/azure/cosmos-db/secure-access-to-data#:~:text=Open%20the%20Azure%20portal%2C%20and,user%2C%20group%2C%20or%20application
upvoted 30 times
rdemontis
3 years, 6 months ago
Thanks, very good explanation!
upvoted 1 times
...
leo_az300
3 years, 8 months ago
thanks for explanation, much better than simply saying "answer is correct"
upvoted 7 times
...
Jeanphi72
3 years, 2 months ago
FYI: Outdated explanation see the link for more information
upvoted 1 times
...
...
OCHT
Most Recent 3 years ago
Selected Answer: C
Verified. Even , some URL explanations are outdated.
upvoted 1 times
...
cwilson91
3 years, 1 month ago
On AZ-305 exam - 5.7.22
upvoted 3 times
...
Dawn7
3 years, 3 months ago
Selected Answer: C
C seems correct
upvoted 1 times
...
Eitant
3 years, 6 months ago
Selected Answer: C
Correct answer
upvoted 1 times
...
syu31svc
3 years, 8 months ago
A shared access signature (SAS) is a URI that grants restricted access rights to Azure Storage resources -> This makes A wrong B is completely irrelevant so it's wrong as well Azure Information Protection (AIP) is a cloud-based solution that enables organizations to classify and protect documents and emails by applying labels. -> D is wrong as well It can only be C as the answer
upvoted 4 times
...
Gautam1985
3 years, 9 months ago
correct
upvoted 1 times
...
bbcz
4 years, 1 month ago
On Exam 05/01/2021
upvoted 6 times
cfsxtuv33
3 years, 10 months ago
On exam...good to know...what answer did you pick??????
upvoted 1 times
...
...
Vipsao
4 years, 2 months ago
The answer is correct
upvoted 2 times
...
glam
4 years, 4 months ago
C. a resource token and an Access control (IAM) role assignment
upvoted 1 times
...
Blaaa
4 years, 5 months ago
C is correct
upvoted 1 times
...
peacegrace
4 years, 5 months ago
Answer should be correct based on this : https://docs.microsoft.com/en-us/azure/cosmos-db/secure-access-to-data#:~:text=Open%20the%20Azure%20portal%2C%20and,user%2C%20group%2C%20or%20application.
upvoted 1 times
...
anandpsg101
4 years, 5 months ago
Correct answer
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...