AZ-500 exam dumps

AZ-500 practice question 145 of 273

Microsoft Azure Security Technologies. Associate level, Microsoft. Free question with the correct answer and a full explanation.

AZ-500 Question 145

Select 2

You manage an Azure Storage account that hosts confidential financial records for your organization. You must ensure that your data is encrypted at rest using your own keys stored in Azure Key Vault and that all data transfers occur only over secure connections. You also want to retain existing security settings for virtual network integration. Which two configurations should you implement to meet these requirements?

  1. A

    Disable secure transfer in the Storage Account settings to allow all connection types

  2. B

    Enable customer-managed keys for the Storage Account with an Azure Key Vault key

  3. C

    Use Azure Active Directory Domain Services to manage data encryption at rest

  4. D

    Set 'Secure transfer required' to Enabled for the Storage Account

  5. E

    Switch the Storage Account to service-managed keys in the Keys blade

Show answer and explanation

Correct answers: B, D

Explanation

To meet strict security requirements, you should combine customer-managed keys with mandatory secure connections. Customer-managed keys in Azure Key Vault satisfy the requirement for encryption at rest with your own cryptographic material, while enabling 'Secure transfer required' ensures that data connections always use TLS/HTTPS. Azure documentation (https://learn.microsoft.com/azure/storage/common/storage-service-encryption and https://learn.microsoft.com/azure/storage/common/storage-require-secure-transfer) outlines these best practices and how to implement them.

  • A. Incorrect.

    Incorrect. Disabling secure transfer would undermine security and allow unencrypted connections. This goes against the requirement for secure data transfers.

  • B. Correct.

    Correct. To satisfy the requirement for encryption at rest with your own keys, you need to enable customer-managed keys and reference a key in Azure Key Vault.

  • C. Incorrect.

    Incorrect. Azure AD Domain Services doesn't manage data encryption at rest for Azure Storage. This option conflates identity services with encryption key management requirements.

  • D. Correct.

    Correct. Setting 'Secure transfer required' to Enabled ensures that all data connections use HTTPS, meeting the requirement to allow only secure connections.

  • E. Incorrect.

    Incorrect. Switching to service-managed keys would revert to the default, platform-managed encryption, which does not fulfill the requirement of using your own cryptographic keys.

Timed practice exam

Take a AZ-500 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam