SC-100 Design security solutions for infrastructure Practice Question
You are designing a security solution for an Azure environment that includes several storage accounts containing sensitive data. The company requires that all data in transit to the storage accounts be encrypted and that access be restricted to specific virtual networks. You need to recommend a solution that enforces these requirements and provides visibility into any non-compliant storage accounts. What should you recommend?
⚠ Common exam trap
The trap here is assuming that Azure Private Link alone satisfies encryption in transit requirements, when in fact secure transfer must be explicitly enabled to enforce HTTPS for all connections.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable secure transfer required on all storage accounts and configure network rules to allow access only from selected virtual networks and IP addresses. Use Azure Policy to deny creation of storage accounts that do not meet these settings.
The requirements are to enforce encryption in transit and restrict network access to specific virtual networks. Enabling secure transfer required ensures that all requests to the storage account use HTTPS, enforcing encryption in transit. Network rules can be configured to allow access only from selected virtual networks and IP addresses. Azure Policy with a deny effect ensures that new storage accounts cannot be created without these settings, providing preventive enforcement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enable secure transfer required on all storage accounts and configure network rules to allow access only from selected virtual networks and IP addresses. Use Azure Policy to deny creation of storage accounts that do not meet these settings.
Why this is correct
Enabling secure transfer required enforces encryption in transit, and network rules restrict access to specific virtual networks. Azure Policy with a deny effect prevents the creation of non-compliant storage accounts, ensuring enforcement. This combination meets both the encryption and network restriction requirements while providing preventive control.
- ✗
Deploy a network virtual appliance (NVA) to inspect all traffic to storage accounts and enforce encryption. Use Azure Policy to audit compliance.
Why it's wrong here
An NVA can inspect traffic but cannot enforce encryption for storage account connections because encryption is negotiated between the client and the storage service. NVAs are also complex to manage and do not provide native enforcement. Azure Policy auditing alone does not enforce the requirements, making this approach ineffective and overly complex.
- ✗
Configure Azure Policy to audit storage accounts that do not require secure transfer and that allow access from all networks. Enable Defender for Storage to detect anomalies.
Why it's wrong here
Azure Policy can audit non-compliant storage accounts, and Defender for Storage provides threat detection, but this combination does not enforce the requirements. It only reports on non-compliance and detects threats after the fact. The company needs to enforce encryption in transit and network restrictions, which requires a preventive control, not just auditing and detection.
- ✗
Use Azure Private Link to create private endpoints for all storage accounts and disable public access. Enable Microsoft Defender for Storage for threat detection.
Why it's wrong here
Private Link and private endpoints restrict access to the virtual network, but they do not enforce encryption in transit for all connections. While private endpoints use the Azure backbone, the requirement explicitly states encryption in transit, which is best addressed by the secure transfer setting. Defender for Storage provides detection but does not enforce the encryption requirement.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.