Courseiva

AZ-500 Secure compute, storage, and databases Practice Question

Which TWO actions should you take to ensure that an Azure Storage account is only accessible over HTTPS and that data in transit is encrypted?

⚠ Common exam trap

Candidates often confuse 'Secure transfer required' with 'minimum TLS version' or think that Azure Firewall or Private Link alone can enforce encryption, but neither of those services actually enforces HTTPS or TLS for data in transit.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Set 'Secure transfer required' to Enabled.

Enabling 'Secure transfer required' on an Azure Storage account rejects any HTTP requests and enforces HTTPS for all data in transit. Option D is correct because setting the minimum TLS version to 1.2 ensures that only clients using TLS 1.2 or higher can connect, which prevents downgrade attacks and enforces strong encryption for data in transit.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure a custom domain with HTTPS enabled.

    Why it's wrong here

    Configuring a custom domain with HTTPS enabled does not force all storage clients to use TLS. Requests sent directly to the default storage endpoint (such as `myaccount.blob.core.windows.net`) or via shared access signatures could still be made over plain HTTP unless the account's 'Secure transfer required' setting is turned on. The custom domain simply provides a branded URL with TLS support; it is not an encryption policy for every potential request path.

  • ✓

    Set 'Secure transfer required' to Enabled.

    Why this is correct

    Setting 'Secure transfer required' to Enabled instructs Azure Storage to reject any request that arrives over plain HTTP, returning an error such as 403 Forbidden for non-HTTPS attempts. This enforces that all data transmitted to or from blob, table, queue, and file endpoints must use TLS/HTTPS, regardless of whether the client uses the public endpoint, a custom domain, or a shared access signature. It is the primary control that makes encryption-in-transit mandatory for the storage account.

  • ✗

    Deploy Azure Firewall in front of the storage account.

    Why it's wrong here

    Deploying Azure Firewall in front of the storage account restricts traffic based on source IP addresses, ports, and network rules, but it does not inspect or require encryption for the application payload. Clients can still initiate plain HTTP connections through allowed firewall rules, so the data would travel unencrypted between the client and the storage service. The firewall controls connectivity, not how TLS is used; therefore, it cannot be used to meet an encryption-in-transit requirement.

  • ✓

    Set the minimum TLS version to 1.2.

    Why this is correct

    Setting the minimum TLS version to 1.2 forces clients that do negotiate an HTTPS connection to use a current, cryptographically secure protocol, blocking older TLS 1.0 and 1.1 handshakes that are more vulnerable to attacks. This complements 'Secure transfer required' by raising the security floor for the encryption that is already being used. Without this setting, a client could still connect using HTTPS but with an outdated and weaker TLS version.

  • ✗

    Use Azure Private Link to connect to the storage account.

    Why it's wrong here

    Using Azure Private Link to connect to the storage account gives a private IP address in your virtual network and routes traffic over the Microsoft backbone, removing exposure to the public internet. It does not alter the storage account's encryption requirements because traffic over that private link can still be sent as plain HTTP if the client chooses to connect that way. Private Link is a networking topology feature, not a transport-layer encryption control, so it cannot ensure that all requests are encrypted.

About these practice questions

One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.