Courseiva

AZ-500 Secure compute, storage, and databases Practice Question

Your organization uses Azure Storage to host sensitive financial data. You need to ensure that all access to the storage account is encrypted in transit and that access keys are rotated automatically every 90 days. You also need to prevent access from public IP addresses. Which combination of configurations should you implement?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable 'Secure transfer required', configure key rotation policy, and set 'Public network access' to 'Disabled'

It directly satisfies all three requirements: enabling 'Secure transfer required' enforces HTTPS/TLS encryption in transit, configuring a key rotation policy automatically rotates the storage account access keys on a 90-day schedule, and setting 'Public network access' to 'Disabled' blocks access from public IP addresses (forcing private endpoint/private link access). The other options fall short: A relies on manual key rotation and a blanket firewall block rather than automatic rotation, B disables storage account key access (which conflicts with rotating access keys) and does not disable public network access, and C disables only anonymous blob public access, which does not prevent access from public IP addresses.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure a network firewall rule to block all traffic, enable 'Secure transfer required', and rotate keys manually every 90 days

    Why it's wrong here

    While 'Secure transfer required' enforces HTTPS, a network firewall rule that blocks all traffic is not the same as disabling the public endpoint; it also blocks legitimate users and Azure services unless paired with complex exceptions. Manual key rotation every 90 days is error-prone and can be missed, leaving keys active indefinitely if an administrator forgets to rotate them. This option fails because it relies on manual operation and an overly broad network rule instead of automated rotation and a controlled public-access baseline.

  • ✗

    Enable 'Allow trusted Microsoft services', configure key rotation policy, and disable 'Allow storage account key access'

    Why it's wrong here

    Enabling 'Allow trusted Microsoft services' only adds an exception for specific Microsoft platform services; it does not close the storage account's public endpoint and does not enforce HTTPS, so clients can still transmit data over HTTP from any public IP. Disabling 'Allow storage account key access' prevents shared-key authentication, but it still allows Microsoft Entra ID-authenticated access from public endpoints and does not guarantee that the configured key rotation policy is actually rotating keys. This combination misses secure-transfer enforcement and leaves the public network surface exposed.

  • ✗

    Enable 'Secure transfer required', configure key rotation policy, and disable 'Allow Blob public access'

    Why it's wrong here

    Although this option enables 'Secure transfer required' and a key rotation policy, disabling 'Allow Blob public access' only prevents anonymous read access to blob containers; it does not restrict the public endpoint of the storage account. Authenticated users or attackers with valid credentials can still access blobs, files, queues, and tables from any public IP, especially if credentials are leaked. To protect sensitive financial data, you must explicitly set 'Public network access' to Disabled so the entire public endpoint is removed, not just anonymous blob access.

  • ✓

    Enable 'Secure transfer required', configure key rotation policy, and set 'Public network access' to 'Disabled'

    Why this is correct

    This is the correct configuration because it addresses three independent layers of protection. 'Secure transfer required' forces all clients to use HTTPS and reject HTTP requests; the key rotation policy automatically rotates shared account keys within a defined period, limiting the lifetime of any leaked key; and 'Public network access: Disabled' blocks the storage account's public endpoint entirely, requiring connections to come through private endpoints or approved virtual network paths. Together these controls provide defense-in-depth for sensitive financial data.

About these practice questions

One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.