AZ-500 exam dumps

AZ-500 practice question 147 of 273

Microsoft Azure Security Technologies. Associate level, Microsoft. Free question with the correct answer and a full explanation.

AZ-500 Question 147

Single answer

You are an Azure Security Engineer for a financial services company that stores confidential data in an Azure Storage account. Your compliance policy requires that you have exclusive control over encryption keys and that you must rotate these keys regularly. Additionally, you must ensure data in transit to and from the storage account is always encrypted. Which approach best meets these requirements?

  1. A

    A. Enable 'Secure transfer required' and configure customer-managed keys stored in Azure Key Vault for the storage account.

  2. B

    B. Allow both HTTP and HTTPS traffic to the storage account while relying on Microsoft-managed keys for encryption.

  3. C

    C. Use client-side encryption libraries only and skip configuring encryption settings in Azure.

  4. D

    D. Use the storage account's default encryption with Microsoft-managed keys and enable 'Secure transfer required'.

Show answer and explanation

Correct answer: A

Explanation

The best practice for meeting both key control and encryption-in-transit requirements is to enable 'Secure transfer required' so all data traffic uses HTTPS, and implement customer-managed keys in Azure Key Vault. This strategy ensures you remain in control of rotation schedules and permissions for those keys. For more information, refer to Microsoft’s documentation on 'Azure Storage encryption for data at rest' and 'Security recommendations for Blob storage' in Azure.

  • A. Correct.

    A. This option ensures that all connections use HTTPS only (reducing the risk of data interception), and storing customer-managed keys in Azure Key Vault gives you exclusive control and allows you to implement key rotation schedules. This meets both the encryption-in-transit and encryption-at-rest requirements with your own keys.

  • B. Incorrect.

    B. Allowing HTTP traffic does not fulfill the requirement to enforce encrypted connections. Relying on Microsoft-managed keys does not give you exclusive control over key rotation, so this option does not satisfy your compliance policy.

  • C. Incorrect.

    C. While client-side encryption can be an additional layer of security, relying solely on client-side encryption without Azure-level encryption configuration does not guarantee compliance with the organization’s strict key control policies. It also does not enforce secure transfer in transit at the service level.

  • D. Incorrect.

    D. Enabling 'Secure transfer required' will force HTTPS connections, which is beneficial. However, using Microsoft-managed keys means you do not have exclusive control or rotation capability over the keys. This violates the requirement for customer-side key management.

Timed practice exam

Take a AZ-500 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam