Configuring supportsHttpsTrafficOnly to true enforces that all client requests to the storage account must be made over HTTPS, causing any HTTP request to be rejected. The minimumTlsVersion property set to TLS1_2 further ensures that connections use at least TLS version 1.2, blocking older protocols such as TLS 1.0 and 1.1. Together, these two properties provide complete transport security enforcement, which is exactly what the requirement asks for.
Why this answer
The `supportsHttpsTrafficOnly` property enforces that all traffic to the storage account must use HTTPS, and the `minimumTlsVersion` property set to `TLS1_2` ensures that only TLS 1.2 or higher is accepted. Together, these two properties satisfy the requirement of HTTPS-only access with TLS 1.2, as defined in the Azure Storage security baseline.
Exam trap
The trap here is that candidates often confuse `supportsHttpsTrafficOnly` with a simple boolean toggle and forget that `minimumTlsVersion` is a separate, required property to enforce the specific TLS version, leading them to select an option that only partially addresses the requirement.
How to eliminate wrong answers
Option A is wrong because the `type` property only declares the resource provider and type (`Microsoft.Storage/storageAccounts`), not any security settings for HTTPS or TLS. Option B is wrong because `accessTier: Hot` controls the storage tier (Hot, Cool, Archive) for blob data, not transport security protocols. Option D is wrong because the `name` property simply assigns the storage account name (`stprod001`) and has no effect on HTTPS or TLS enforcement.