AZ-500 Practice Question: Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel
Your organization uses Microsoft Defender for Cloud to protect Azure resources. You need to ensure that storage accounts are only accessible via HTTPS. What should you configure?
⚠ Common exam trap
Candidates often confuse network-level controls (firewall, private endpoint) with protocol-level enforcement, mistakenly thinking they can block HTTP when they only restrict network access or provide private connectivity.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable 'Secure transfer required' in the storage account's configuration
Enabling 'Secure transfer required' on a storage account enforces HTTPS for all requests to the storage account, rejecting any HTTP traffic. This setting ensures that data in transit is encrypted using TLS, which aligns with the requirement to only allow HTTPS access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure a storage account firewall to block HTTP
Why it's wrong here
A storage account firewall filters traffic by source IP address or virtual network subnet, not by the application-layer protocol being used. Because both HTTP and HTTPS requests originate from the same allowed client and use the same network path, the firewall cannot distinguish or block one protocol without blocking both. Rejecting HTTP is an account-level configuration that requires enabling 'Secure transfer required', so a firewall does not satisfy the requirement to enforce HTTPS.
- ✗
Use a private endpoint for the storage account
Why it's wrong here
A private endpoint exposes the storage account to a virtual network through a private IP address and routes traffic over Microsoft's backbone, but it does not inspect or alter the protocol between client and service. Requests sent to a private endpoint can still use HTTP unless the storage account explicitly denies them. This is a network-isolation control for protecting the data path from public exposure, not a transport-encryption enforcement setting.
- ✓
Enable 'Secure transfer required' in the storage account's configuration
Why this is correct
Enabling 'Secure transfer required' (the supportsHttpsTrafficOnly property) makes Azure Storage reject any request sent over HTTP, including requests via the REST API, Azure SDKs, and file shares, and returns an error requiring the client to use HTTPS. It forces all data-plane traffic to be encrypted in transit and can be combined with a minimum TLS version for further control. This is the account-level control that directly implements the requirement to disallow insecure HTTP.
- ✗
Create an Azure Policy to audit storage accounts that do not require secure transfer
Why it's wrong here
An Azure Policy with the Audit effect only evaluates whether storage accounts have the SupportsHttpsTrafficOnly property set to true and reports them as non-compliant in compliance logs. It does not change the account's configuration, block HTTP traffic, or remediate the setting. To actually require secure transfer, you need an enforcement policy using Deny, DeployIfNotExists, or Modify to set the property, or manually enable the setting.
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.