You need to secure an Azure Storage account that will host sensitive data. Which TWO configurations should you implement?
Enabling 'Secure transfer required' enforces HTTPS by rejecting all requests made over HTTP, ensuring that every interaction with the storage account is encrypted with TLS. This is a fundamental security baseline that protects data in transit from interception and man-in-the-middle attacks. It is a mandatory control for sensitive data and works in conjunction with private endpoints to guarantee end-to-end encryption.
Why this answer
Option B is correct because enabling 'Secure transfer required' on the storage account enforces HTTPS/TLS for all requests to the storage endpoints, rejecting any HTTP traffic so sensitive data is never transmitted in cleartext. Option E is correct because configuring a private endpoint assigns the storage account a private IP address inside your virtual network via Azure Private Link, removing exposure to the public internet and letting access flow only over the Microsoft backbone network. Option A is not correct here because a SAS is a delegated, time-limited access token for granting scoped permissions to clients, not a baseline network or transport security configuration for the account.
Option C is not correct because allowing public network access from all networks does the opposite of securing the account, exposing it to the internet. Option D is not correct because enabling Azure Files simply turns on the SMB/NFS file share service and does not itself harden or restrict access to the storage account.