Courseiva

MS-102 Deploy and manage a Microsoft 365 tenant Practice Question

Exhibit

Refer to the exhibit.

```json
{
  "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
  "contentVersion": "1.0.0.0",
  "resources": [
    {
      "type": "Microsoft.Storage/storageAccounts",
      "apiVersion": "2021-02-01",
      "name": "[parameters('storageAccountName')]",
      "location": "eastus",
      "kind": "StorageV2",
      "sku": {
        "name": "Standard_LRS"
      },
      "properties": {
        "supportsHttpsTrafficOnly": true
      }
    }
  ]
}
```

You are reviewing an ARM template that will be used to deploy a storage account for a Microsoft 365 migration project. The template includes 'supportsHttpsTrafficOnly': true. What is the primary benefit of this setting?

⚠ Common exam trap

Many exam-takers confuse 'supportsHttpsTrafficOnly' with performance or redundancy features, but it is purely a security control for enforcing encrypted transport.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

It enforces secure transfer (HTTPS) for all requests to the storage account.

Setting 'supportsHttpsTrafficOnly' to true enforces secure transfer by requiring all requests to the storage account to use HTTPS (TLS). This ensures data in transit is encrypted, protecting against man-in-the-middle attacks and eavesdropping. It is a critical security control for compliance with standards like PCI-DSS and HIPAA.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    It enforces secure transfer (HTTPS) for all requests to the storage account.

    Why this is correct

    The supportsHttpsTrafficOnly property (also known as enableHttpsTrafficOnly in ARM templates) blocks any HTTP request to the storage account, forcing clients to use TLS/HTTPS for all read, write, and management operations. This prevents data from being transmitted in cleartext, meeting security and compliance requirements such as PCI DSS and HIPAA. Without this flag, a misconfigured client could silently fall back to HTTP, exposing account keys and data in transit.

  • ✗

    It reduces latency by enabling CDN integration.

    Why it's wrong here

    CDN integration is entirely separate from secure transfer enforcement—Azure CDN or Front Door is used to cache blobs and static content at edge points of presence to reduce round-trip latency. The HTTPS-only property does not provision or configure any CDN endpoint, so it has no effect on network distance or caching. In fact, enabling HTTPS can add a small amount of latency because of the TLS handshake, so this option is incorrect.

  • ✗

    It enables geo-redundant storage.

    Why it's wrong here

    Geo-redundant storage (GRS/RA-GRS) is determined by the storage account's SKU (for example, Standard_GRS or Standard_RAGRS) and its replication settings, not by the HTTPS enforcement flag. The supportsHttpsTrafficOnly property only governs the transport protocol for client requests; it does not alter the replication strategy or the physical location of data copies. Setting HTTPS enforcement would leave the account as LRS if that SKU is chosen, so it cannot enable geo-redundancy.

  • ✗

    It minimizes storage costs by reducing bandwidth usage.

    Why it's wrong here

    Enforcing HTTPS does not reduce bandwidth usage—TLS encryption adds overhead (handshake bytes and slightly larger packets), so it can marginally increase the amount of data transmitted. Bandwidth and storage costs are driven by the actual bytes read/written and the selected access tier (Hot/Cool/Archive), not by the transport protocol. Since the setting blocks HTTP and requires HTTPS, it would not minimize costs; it could only incur a tiny extra compute/bandwidth cost for encryption.

About these practice questions

One of 712 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.