Courseiva

SC-100 Practice Question: Design security solutions for applications and data

You are designing a solution to protect sensitive data in Azure Blob Storage. The data must be encrypted at rest using customer-managed keys (CMK) stored in Azure Key Vault. Additionally, you need to ensure that only specific virtual networks can access the storage account, and all access must be logged. Which three configurations should you implement? (Choose three.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable Azure Storage logging for read and write requests

Option B is correct because the scenario explicitly requires encryption at rest with customer-managed keys (CMK) stored in Azure Key Vault, which is achieved by configuring the storage account to use CMK encryption referencing a Key Vault key. Option C is correct because restricting access to specific virtual networks requires configuring the storage account firewall (network rules) and enabling a virtual network service endpoint (Microsoft.Storage) on the designated subnets so traffic reaches the storage account over the Azure backbone. Option A is correct because the requirement that all access be logged is satisfied by enabling Azure Storage logging (diagnostic logging for read and write requests) for the blob service, capturing authentication and access details. Option D is incorrect because Azure Files encryption at rest is unrelated to Blob Storage and does not address CMK, network restriction, or logging for blobs. Option E is incorrect because soft delete for blobs is a data-protection/recovery feature that retains deleted blobs; it does not provide encryption with CMK, network access control, or access logging.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Enable Azure Storage logging for read and write requests

    Why this is correct

    Enabling Azure Storage logging captures read and write requests against blobs, producing the audit trail the scenario demands. Diagnostic logging records authenticated access details, satisfying the requirement that all access to the sensitive data be logged for later review.

  • ✓

    Enable Azure Storage encryption with customer-managed keys in Key Vault

    Why this is correct

    Customer-managed keys in Azure Key Vault encrypt blob data at rest, giving the organisation control over key rotation and revocation rather than relying on Microsoft-managed keys. This directly satisfies the stated CMK encryption requirement for sensitive data.

  • ✓

    Configure a firewall and virtual network service endpoint for the storage account

    Why this is correct

    Network rules on the storage account restrict access to selected virtual networks and public IP ranges, and service endpoints give the subnet a direct private path to the service. This satisfies the requirement that only specific virtual networks may reach the account, while logging remains separate.

  • ✗

    Enable Azure Files encryption at rest

    Why it's wrong here

    Azure Files encryption at rest applies to file shares, not Blob Storage, and platform-side encryption is already enabled regardless of CMK configuration. It tempts because it is a real storage encryption setting, and would be correct if the workload used Azure Files and needed to confirm encryption at rest there.

  • ✗

    Enable soft delete for blobs

    Why it's wrong here

    Soft delete protects against accidental deletion by retaining recoverable blobs; it neither encrypts data with customer-managed keys nor restricts network access nor produces access logs. It tempts because it is a genuine data-protection control, and would be correct if the requirement were recoverability after deletion rather than encryption, network restriction and logging.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

Quick reference

Azure Blob Storage Tier Comparison

TierStorage CostRetrieval CostLatencyUse Case
HotHighestLowestImmediateActive data, frequent reads
CoolLowerHigherImmediateData accessed < once / month
ColdLower stillHigherImmediateData accessed < once / quarter
ArchiveLowestHighest + rehydration delayHoursLong-term compliance retention

About these practice questions

One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.