Courseiva

AZ-500 Secure compute, storage, and databases Practice Question

You need to secure an Azure Storage account that will host sensitive data. Which TWO configurations should you implement?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable 'Secure transfer required'

Option B is correct because enabling 'Secure transfer required' on the storage account enforces HTTPS/TLS for all requests to the storage endpoints, rejecting any HTTP traffic so sensitive data is never transmitted in cleartext. Option E is correct because configuring a private endpoint assigns the storage account a private IP address inside your virtual network via Azure Private Link, removing exposure to the public internet and letting access flow only over the Microsoft backbone network. Option A is not correct here because a SAS is a delegated, time-limited access token for granting scoped permissions to clients, not a baseline network or transport security configuration for the account. Option C is not correct because allowing public network access from all networks does the opposite of securing the account, exposing it to the internet. Option D is not correct because enabling Azure Files simply turns on the SMB/NFS file share service and does not itself harden or restrict access to the storage account.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Generate a shared access signature (SAS)

    Why it's wrong here

    A shared access signature (SAS) is a delegated authorization mechanism that grants time-limited, permission-scoped access to storage resources, but it does not enforce transport encryption or control network exposure. It is an access-control token, not a security baseline for the storage account itself. Without first securing the transport layer and network boundary, a SAS can still allow data to be intercepted or the account to be reached by unauthorized parties.

  • ✓

    Enable 'Secure transfer required'

    Why this is correct

    Enabling 'Secure transfer required' enforces HTTPS by rejecting all requests made over HTTP, ensuring that every interaction with the storage account is encrypted with TLS. This is a fundamental security baseline that protects data in transit from interception and man-in-the-middle attacks. It is a mandatory control for sensitive data and works in conjunction with private endpoints to guarantee end-to-end encryption.

  • ✗

    Allow public network access from all networks

    Why it's wrong here

    Configuring the storage account to allow public network access from all networks exposes the service endpoints to the entire internet, dramatically increasing the attack surface. Any unauthenticated or weakly authenticated client can attempt to reach the account, making it more vulnerable to brute-force, credential-stuffing, or other internet-based attacks. A secure baseline for sensitive data must restrict public access to selected virtual networks or disable it entirely.

  • ✗

    Enable Azure Files

    Why it's wrong here

    Azure Files is a fully managed file-share service that offers SMB and NFS file shares in the cloud, but it is a service offering rather than a security control. Enabling Azure Files does nothing to enforce transport encryption, restrict network access, or strengthen identity-based access controls. A security baseline requires configuration changes that improve the storage account's security posture, not the activation of additional storage features.

  • ✓

    Configure a private endpoint

    Why this is correct

    Configuring a private endpoint assigns the storage account a private IP address from your virtual network, allowing clients to connect over Microsoft's private network without traversing the public internet. This eliminates exposure to internet-based threats and supports compliance requirements for network isolation. To be effective, it should be combined with disabling public network access, creating a strong security boundary for sensitive data.

About these practice questions

One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.