MS-102 Deploy and manage a Microsoft 365 tenant Practice Question
Exhibit
Refer to the exhibit.
```json
{
"$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
"contentVersion": "1.0.0.0",
"resources": [
{
"type": "Microsoft.Storage/storageAccounts",
"apiVersion": "2021-02-01",
"name": "[parameters('storageAccountName')]",
"location": "eastus",
"kind": "StorageV2",
"sku": {
"name": "Standard_LRS"
},
"properties": {
"supportsHttpsTrafficOnly": true
}
}
]
}
```You are reviewing an ARM template that will be used to deploy a storage account for a Microsoft 365 migration project. The template includes 'supportsHttpsTrafficOnly': true. What is the primary benefit of this setting?
⚠ Common exam trap
Many exam-takers confuse 'supportsHttpsTrafficOnly' with performance or redundancy features, but it is purely a security control for enforcing encrypted transport.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It enforces secure transfer (HTTPS) for all requests to the storage account.
Setting 'supportsHttpsTrafficOnly' to true enforces secure transfer by requiring all requests to the storage account to use HTTPS (TLS). This ensures data in transit is encrypted, protecting against man-in-the-middle attacks and eavesdropping. It is a critical security control for compliance with standards like PCI-DSS and HIPAA.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
It enforces secure transfer (HTTPS) for all requests to the storage account.
Why this is correct
The supportsHttpsTrafficOnly property (also known as enableHttpsTrafficOnly in ARM templates) blocks any HTTP request to the storage account, forcing clients to use TLS/HTTPS for all read, write, and management operations. This prevents data from being transmitted in cleartext, meeting security and compliance requirements such as PCI DSS and HIPAA. Without this flag, a misconfigured client could silently fall back to HTTP, exposing account keys and data in transit.
- ✗
It reduces latency by enabling CDN integration.
Why it's wrong here
CDN integration is entirely separate from secure transfer enforcement—Azure CDN or Front Door is used to cache blobs and static content at edge points of presence to reduce round-trip latency. The HTTPS-only property does not provision or configure any CDN endpoint, so it has no effect on network distance or caching. In fact, enabling HTTPS can add a small amount of latency because of the TLS handshake, so this option is incorrect.
- ✗
It enables geo-redundant storage.
Why it's wrong here
Geo-redundant storage (GRS/RA-GRS) is determined by the storage account's SKU (for example, Standard_GRS or Standard_RAGRS) and its replication settings, not by the HTTPS enforcement flag. The supportsHttpsTrafficOnly property only governs the transport protocol for client requests; it does not alter the replication strategy or the physical location of data copies. Setting HTTPS enforcement would leave the account as LRS if that SKU is chosen, so it cannot enable geo-redundancy.
- ✗
It minimizes storage costs by reducing bandwidth usage.
Why it's wrong here
Enforcing HTTPS does not reduce bandwidth usage—TLS encryption adds overhead (handshake bytes and slightly larger packets), so it can marginally increase the amount of data transmitted. Bandwidth and storage costs are driven by the actual bytes read/written and the selected access tier (Hot/Cool/Archive), not by the transport protocol. Since the setting blocks HTTP and requires HTTPS, it would not minimize costs; it could only incur a tiny extra compute/bandwidth cost for encryption.
Go deeper
Related to this question
Learn chapter
Microsoft Secure Score
Key term
Security control
A security control is a safeguard or countermeasure designed to protect the confidentiality, integrity, and availability of information systems and data.
Key term
Compliance
Compliance is the process of ensuring that an organization follows laws, regulations, standards, and internal policies that apply to its operations and data handling.
About these practice questions
One of 712 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.