AZ-500 Secure compute, storage, and databases Practice Question
Exhibit
{
"$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
"contentVersion": "1.0.0.0",
"resources": [
{
"type": "Microsoft.Storage/storageAccounts",
"apiVersion": "2023-01-01",
"name": "mystorageaccount",
"location": "[resourceGroup().location]",
"sku": {
"name": "Standard_GRS"
},
"kind": "StorageV2",
"properties": {
"supportsHttpsTrafficOnly": true,
"encryption": {
"keySource": "Microsoft.Storage"
}
}
}
]
}Refer to the exhibit. You are reviewing an ARM template for an Azure Storage account. Which of the following is true about the deployment?
⚠ Common exam trap
In Azure exams, candidates often confuse the ARM template properties for encryption (e.g., 'encryption.keySource') with those for network access (e.g., 'networkAcls'). Also, the distinction between storage SKU redundancy levels (LRS, GRS, RA-GRS, ZRS) is frequently tested, and many mistakenly think 'Standard_GRS' means only geo-redundancy without understanding that HTTPS enforcement is a separate property.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The storage account will enforce HTTPS traffic and replicate data to a paired region.
The ARM template configures the storage account with the 'supportsHttpsTrafficOnly' property set to true, which enforces HTTPS for all requests. Additionally, the 'sku.name' is set to 'Standard_GRS', which replicates data to a paired region for geo-redundancy. Therefore, option D correctly identifies both HTTPS enforcement and geo-replication to a paired region.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The storage account will use customer-managed keys from Azure Key Vault.
Why it's wrong here
The ARM template's encryption block sets 'keySource' to 'Microsoft.Storage', indicating that Azure automatically manages the encryption keys on behalf of the tenant. With customer-managed keys, the template would instead set 'keySource' to 'Microsoft.Keyvault' and provide the full key URI from an Azure Key Vault, along with a managed identity for the storage account. Because those Key Vault references are absent, the account is encrypted with Microsoft-managed keys, not customer-managed keys.
- ✗
The storage account will use locally redundant storage (LRS).
Why it's wrong here
The template declares the SKU as 'Standard_GRS', which is geo-redundant storage, not locally redundant storage. LRS would use the 'Standard_LRS' SKU and keep only three synchronous copies within the primary region. In contrast, 'Standard_GRS' copies data three times in the primary region and then asynchronously replicates it to a paired secondary region, providing geo-redundancy that LRS does not offer.
- ✗
The storage account will have a firewall rule to restrict access to specific IPs.
Why it's wrong here
The storage account in the template does not include a 'networkAcls' property, so it falls back to the default behavior of allowing traffic from any network. To restrict access to specific IP addresses, the template would need to set 'defaultAction' to 'Deny' and provide an 'ipRules' array with allowed CIDR ranges. Since no such deny rule or allow list is present, the account is not restricted to specific IPs.
- ✓
The storage account will enforce HTTPS traffic and replicate data to a paired region.
Why this is correct
The template sets 'supportsHttpsTrafficOnly' to true, which enforces HTTPS for all client requests and rejects any plaintext HTTP traffic. Additionally, the 'Standard_GRS' SKU enables geo-redundant replication, storing copies in both the primary region and a paired secondary region for disaster recovery. Together, these properties guarantee secure HTTPS-only traffic and automatic data replication to the paired region, which makes this statement correct.
Go deeper
Related to this question
About these practice questions
One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.