AZ-500 exam dumps

AZ-500 practice question 168 of 273

Microsoft Azure Security Technologies. Associate level, Microsoft. Free question with the correct answer and a full explanation.

AZ-500 Question 168

Select 2

You are developing a new Azure Storage account for an application that handles highly sensitive financial data. Your compliance requirements state that data at rest must be protected by two layers of encryption at the infrastructure level. Which two statements accurately describe the steps or requirements to enable double encryption (Infrastructure Encryption) for this new storage account?

  1. A
    1. You must enable Infrastructure Encryption when creating the storage account, as it cannot be enabled after creation.
  2. B
    1. You can enable Infrastructure Encryption on existing storage accounts by toggling it in the Encryption blade of the Azure portal.
  3. C
    1. You need to ensure the storage account uses a region that supports Infrastructure Encryption, as not all regions may support this feature.
  4. D
    1. Infrastructure Encryption replaces the default server-side encryption with platform-managed keys, so you must disable server-side encryption first.
Show answer and explanation

Correct answers: A, C

Explanation

Infrastructure Encryption (also referred to as 'double encryption') works by adding an extra layer of encryption at the storage service infrastructure level. According to Microsoft’s documentation, it must be enabled at the time of creating a new storage account, and it does not replace existing server-side encryption. It is also region-specific, so administrators must confirm availability in the chosen region. Further details can be found in the official Azure Storage encryption documentation.

  • A. Correct.

    Option 1 is correct. Infrastructure Encryption must be enabled at the time of storage account creation and cannot be retrofitted afterwards. This aligns with Microsoft’s documentation stating that Infrastructure Encryption is irreversible and must be set during initial configuration.

  • B. Incorrect.

    Option 2 is incorrect. There is no toggle or switch to enable Infrastructure Encryption for existing storage accounts once they are created. The feature is only available during the creation of a new storage account.

  • C. Correct.

    Option 3 is correct. Infrastructure Encryption may not be available in all Azure regions. Ensuring the storage account resides in a supported region is essential for enabling double encryption at the infrastructure level.

  • D. Incorrect.

    Option 4 is incorrect. Infrastructure Encryption does not replace the default server-side encryption with platform-managed keys; it provides an additional layer of encryption. There is no requirement to disable the default server-side encryption.

Timed practice exam

Take a AZ-500 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam