Microsoft Cybersecurity Architect (SC-100)Design security for applications and dataMedium

A research institution is developing a new data analytics platform on Azure that will consolidate sensitive genomic data from various sources. The platform needs to ensure that data access permissions are granular, allowing different research teams to access specific datasets within the data lake, while ensuring that access to the underlying storage is not granted directly to users. The solution must support both identity-based access control and POSIX-like permissions for fine-grained control over files and directories. Which security model should the architect recommend for Azure Data Lake Storage Gen2?

  1. AAzure Storage Account Access Keys
  2. BRole-Based Access Control (RBAC) and Access Control Lists (ACLs)
  3. CShared Access Signatures (SAS)
  4. DService Endpoints
Show answer & explanation

Correct answer: B. Role-Based Access Control (RBAC) and Access Control Lists (ACLs)

Azure Data Lake Storage Gen2 supports a hierarchical namespace, allowing it to combine Azure Role-Based Access Control (RBAC) for broad permissions (e.g., at the container level) with POSIX-like Access Control Lists (ACLs) for granular, file- and directory-level permissions. This combination enables precise control over access for different research teams while leveraging identity-based access.

Why the other options are wrong

  • A. Azure Storage Account Access Keys grant full administrative access to the entire storage account and should be avoided for granular access control, especially for users or applications.
  • C. Shared Access Signatures (SAS) provide delegated access to Azure Storage resources with specific permissions and a validity period. While granular, they are token-based, not identity-based, and can be difficult to manage at scale for complex team structures.
  • D. Service Endpoints enable secure connectivity from a VNet to Azure Storage over the Azure backbone network but do not provide granular access control mechanisms for data within the storage account itself.

Azure Data Lake Storage Gen2 ACLs and RBAC

Azure Data Lake Storage Gen2 combines Azure Role-Based Access Control (RBAC) for broad permissions at the container or storage account level with POSIX-like Access Control Lists (ACLs) for fine-grained, identity-based access control over individual files and directories.

  • Hierarchical namespace support
  • RBAC for coarse-grained permissions
  • POSIX-like ACLs for fine-grained permissions
  • Identity-based access control

Memory trick: RBAC for the forest, ACLs for the trees.

More Design security for applications and data questions