問題文
A team is deciding how an application should authorize to blob storage. Which statement correctly ranks the options from most to least preferable from a security standpoint, and why?
選択肢
- All three are equivalent as long as the storage firewall is configured.
- The account key first, because it is simplest to rotate.
- Microsoft Entra identity with an Azure role, then a user delegation shared access signature, then the account key, because identity-based access is auditable per principal and the account key is not.
- A service shared access signature first, because it is scoped to one service and one resource, then a user delegation signature, then the account key. Identity-based access should be reserved for the cases where per-principal auditing is explicitly required.