SC-100 Practice Question: Design security solutions for applications and data
You are designing a solution to protect sensitive data in Azure Blob Storage. The data must be encrypted at rest using customer-managed keys (CMK) stored in Azure Key Vault. Additionally, you need to ensure that only specific virtual networks can access the storage account, and all access must be logged. Which three configurations should you implement? (Choose three.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable Azure Storage logging for read and write requests
Option B is correct because the scenario explicitly requires encryption at rest with customer-managed keys (CMK) stored in Azure Key Vault, which is achieved by configuring the storage account to use CMK encryption referencing a Key Vault key. Option C is correct because restricting access to specific virtual networks requires configuring the storage account firewall (network rules) and enabling a virtual network service endpoint (Microsoft.Storage) on the designated subnets so traffic reaches the storage account over the Azure backbone. Option A is correct because the requirement that all access be logged is satisfied by enabling Azure Storage logging (diagnostic logging for read and write requests) for the blob service, capturing authentication and access details. Option D is incorrect because Azure Files encryption at rest is unrelated to Blob Storage and does not address CMK, network restriction, or logging for blobs. Option E is incorrect because soft delete for blobs is a data-protection/recovery feature that retains deleted blobs; it does not provide encryption with CMK, network access control, or access logging.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enable Azure Storage logging for read and write requests
Why this is correct
Enabling Azure Storage logging captures read and write requests against blobs, producing the audit trail the scenario demands. Diagnostic logging records authenticated access details, satisfying the requirement that all access to the sensitive data be logged for later review.
- ✓
Enable Azure Storage encryption with customer-managed keys in Key Vault
Why this is correct
Customer-managed keys in Azure Key Vault encrypt blob data at rest, giving the organisation control over key rotation and revocation rather than relying on Microsoft-managed keys. This directly satisfies the stated CMK encryption requirement for sensitive data.
- ✓
Configure a firewall and virtual network service endpoint for the storage account
Why this is correct
Network rules on the storage account restrict access to selected virtual networks and public IP ranges, and service endpoints give the subnet a direct private path to the service. This satisfies the requirement that only specific virtual networks may reach the account, while logging remains separate.
- ✗
Enable Azure Files encryption at rest
Why it's wrong here
Azure Files encryption at rest applies to file shares, not Blob Storage, and platform-side encryption is already enabled regardless of CMK configuration. It tempts because it is a real storage encryption setting, and would be correct if the workload used Azure Files and needed to confirm encryption at rest there.
- ✗
Enable soft delete for blobs
Why it's wrong here
Soft delete protects against accidental deletion by retaining recoverable blobs; it neither encrypts data with customer-managed keys nor restricts network access nor produces access logs. It tempts because it is a genuine data-protection control, and would be correct if the requirement were recoverability after deletion rather than encryption, network restriction and logging.
Visual reference
Quick reference
Azure Blob Storage Tier Comparison
| Tier | Storage Cost | Retrieval Cost | Latency | Use Case |
|---|---|---|---|---|
| Hot | Highest | Lowest | Immediate | Active data, frequent reads |
| Cool | Lower | Higher | Immediate | Data accessed < once / month |
| Cold | Lower still | Higher | Immediate | Data accessed < once / quarter |
| Archive | Lowest | Highest + rehydration delay | Hours | Long-term compliance retention |
Go deeper
Related to this question
About these practice questions
One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.