Courseiva
easyMultiple Choice

SC-100 Practice Question: A company deploys Azure App Service with a custom…

A company deploys Azure App Service with a custom domain and SSL certificate. They want to enforce HTTPS only. Which configuration setting should they enable?

⚠ Common exam trap

Many exam-takers confuse 'HTTPS Only' with 'Minimum TLS Version', thinking that setting a high TLS version also enforces HTTPS, but the latter only restricts the TLS protocol version without redirecting HTTP traffic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

HTTPS Only

The 'HTTPS Only' setting in Azure App Service enforces that all incoming requests are redirected from HTTP to HTTPS, ensuring encrypted communication. This is achieved by returning a 301 redirect for any HTTP request, which aligns with the requirement to enforce HTTPS only.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    HTTPS Only

    Why this is correct

    HTTPS Only is an App Service flag that instructs the front-end load balancer to return a 301/302 redirect for any request arriving over plain HTTP on port 80, sending the client to the same URL with https://. This setting is evaluated before any application code or authentication middleware runs, so it guarantees that no request ever reaches the app unencrypted. It is the direct mechanism to satisfy a requirement that all HTTP traffic be redirected to HTTPS, and it works independently of whether a custom domain or a managed certificate is configured.

  • ✗

    Client Certificates

    Why it's wrong here

    Client Certificates enables mutual TLS (mTLS), which requires the connecting client to present a valid X.509 certificate as part of the TLS handshake before the request is accepted. This setting controls identity verification, not the choice of transport protocol; if a client submits an HTTP request, no TLS handshake occurs at all, so the certificate requirement is never triggered. Enabling this option would not produce an HTTP-to-HTTPS redirect — it would instead reject connection attempts from clients that lack a trusted certificate, which is a completely different security control.

  • ✗

    Minimum TLS Version

    Why it's wrong here

    Minimum TLS Version specifies the oldest TLS protocol version (e.g., TLS 1.2) that the App Service will accept for incoming HTTPS connections. It is enforced only during the TLS negotiation on port 443; it has no influence on requests sent to port 80, because those requests are plaintext and never enter a TLS handshake. Thus, setting a high minimum TLS version does not redirect HTTP traffic to HTTPS and can actually leave HTTP endpoints fully accessible unless HTTPS Only is also enabled, meaning this option addresses cipher-strength policy rather than redirect behavior.

  • ✗

    Custom Domain

    Why it's wrong here

    Custom Domain binds a registered hostname (e.g., www.contoso.com) to the App Service and enables the TLS SNI binding for that domain when a certificate is attached. This setting governs how incoming host headers are routed to the app, but it does not alter the transport mechanism; an HTTP request to the custom domain will still be served over port 80. The custom domain only provides a user-friendly URL and certificate coverage — it does not enforce HTTPS or redirect insecure requests, so it is unrelated to the explicit redirect requirement.

About these practice questions

One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.