A storage account is configured for geo-redundant storage. During a regional incident a developer tries to read the secondary copy directly and cannot. What is the explanation?

Microsoft Certified: Azure Fundamentals (AZ-900), objective architecture-and-services. Azure architecture and services medium

Machine-checked — no person has signed for it. This question was read against the source cited below by an automated pass, which found no contradiction. That is a weaker claim than it sounds: the same kind of process wrote the question, so it can confirm its own mistake.

Treat it as a good draft rather than as settled fact, and read the source below before you rely on it. It is not used in mock exams here — only questions a person has signed for are.

The options

Correct With plain geo-redundant storage the secondary copy is not readable; reading it requires the read-access variant, or a failover to that region

Correct. Plain geo-redundancy keeps the second copy for recovery, not for serving traffic. The read-access variant exists precisely because some designs want to read it.

Not correct The secondary is readable, so this must be a role assignment problem

Wrong diagnosis. A missing role assignment produces an authorisation failure, but here the behaviour is by design: without read access enabled there is no secondary endpoint to authorise against.

Not correct Geo-redundant replication runs once a night, so today's data has not arrived yet

Wrong. Replication to the secondary region is asynchronous but continuous, not a nightly batch. Asynchronous does mean the very latest writes may not have landed, which is what a recovery point objective describes.

Not correct Geo-redundant storage keeps the second copy in the same region, so there is nothing elsewhere to read

Wrong. Geo-redundancy means the secondary lives in the paired region; keeping copies within one region is what the local and zone options do.

Why

Redundancy and readability are separate settings. Geo-redundant storage guarantees a durable second copy in the paired region; read access to that copy is an option you turn on, giving you a second read-only endpoint at the secondary region's address. Designs that plan to serve reads from the secondary during an incident must choose the read-access variant deliberately, and must tolerate data that may be slightly behind.

Where this comes from

Cited
Microsoft AZ-900 study guide skill area architecture-and-services.storage

Practise this

Reading one question is not practice. The trainer will draw a set from objective architecture-and-services and space the ones you get wrong.

Practise Microsoft Certified: Azure Fundamentals (AZ-900)

More questions on this objective

All questions on Azure architecture and services