Courseiva

AZ-500 Secure compute, storage, and databases Practice Question

Exhibit

Refer to the exhibit.
{
  "properties": {
    "encryption": {
      "services": {
        "blob": {
          "enabled": true
        },
        "file": {
          "enabled": true
        }
      },
      "keySource": "Microsoft.Storage"
    }
  }
}

You are reviewing an Azure Resource Manager template for a storage account. The exhibit shows a snippet of the template. Which statement about the template is true?

⚠ Common exam trap

Candidates often assume encryption must be explicitly enabled or that the absence of encryption properties means encryption is disabled, but Azure Storage encryption is always on by default and cannot be turned off.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The storage account will use Microsoft-managed keys for encryption.

The template snippet does not include any encryption-related properties, such as `encryption.keySource` or `encryption.services`, which means the storage account will use the default Microsoft-managed keys for encryption. By default, Azure Storage encrypts all data at rest using Microsoft-managed keys, and no explicit configuration is required. Option C correctly identifies this default behavior.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Encryption is disabled for the storage account.

    Why it's wrong here

    The template does not disable encryption; Azure Storage encryption is enforced at the service level and cannot be turned off. The encryption.services.blob.enabled and encryption.services.file.enabled properties are both set to true, meaning those services are explicitly encrypted. Therefore, the storage account has encryption enabled at rest, not disabled.

  • ✗

    The storage account will use customer-managed keys from Azure Key Vault.

    Why it's wrong here

    Because keySource is Microsoft.Storage, the key management delegation is to Microsoft platform-managed keys, not to a customer-controlled Azure Key Vault key. To request customer-managed keys, the template would need keySource: Microsoft.Keyvault, plus keyvault properties such as keyName, keyVersion, and the Key Vault resource ID. Those elements are not present, so the account does not use customer-managed keys.

  • ✓

    The storage account will use Microsoft-managed keys for encryption.

    Why this is correct

    The encryption.keySource value of Microsoft.Storage indicates Azure's default encryption mechanism, where Microsoft owns, stores, and rotates the AES-256 keys used to encrypt the storage account. This is the platform-managed key model, applied automatically whenever no Key Vault key is referenced. Combined with enabled: true for blob and file, the account will use Microsoft-managed keys for both services.

  • ✗

    Encryption is enabled only for blob storage.

    Why it's wrong here

    The template sets both encryption.services.blob.enabled and encryption.services.file.enabled to true, so encryption is explicitly applied to blob storage and to Azure Files alike. Claiming that encryption is enabled only for blob storage reads the template incorrectly and ignores the file service property. Thus the correct scope of protection spans multiple storage services, not a single one.

About these practice questions

Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.