フリー問題

Implementing End-to-End Security Controls for Cloud and AI Workloads (SC-500) のフリー問題 10 / 20 問目

問題文

A team is deciding how an application should authorize to blob storage. Which statement correctly ranks the options from most to least preferable from a security standpoint, and why?

選択肢

  1. All three are equivalent as long as the storage firewall is configured.
  2. The account key first, because it is simplest to rotate.
  3. Microsoft Entra identity with an Azure role, then a user delegation shared access signature, then the account key, because identity-based access is auditable per principal and the account key is not.
  4. A service shared access signature first, because it is scoped to one service and one resource, then a user delegation signature, then the account key. Identity-based access should be reserved for the cases where per-principal auditing is explicitly required.

解答・解説を確認するには

正解と解説の確認、回答の記録には無料登録が必要です。登録すると演習モードでフリー問題に回答し、正誤と解説をその場で確認できます。