AZ-500 exam dumps

AZ-500 practice question 97 of 273

Microsoft Azure Security Technologies. Associate level, Microsoft. Free question with the correct answer and a full explanation.

AZ-500 Question 97

Select 2

Your organization hosts a web application on Azure App Service with a custom domain, and you also manage an Azure API Management instance that requires encrypted connections. You need to configure TLS so that both your web app and API Management gateway only accept TLS 1.2 or higher. Which two steps should you implement to achieve this requirement?

  1. A

    Upload a valid SSL certificate for your custom domain to Azure App Service and update TLS/SSL settings to enforce a minimum TLS version of 1.2.

  2. B

    Bind a custom domain to the gateway endpoint in API Management and upload a trusted certificate to the custom domain configuration.

  3. C

    Enable TLS 1.0 in Azure App Service to ensure backward compatibility for older clients and devices.

  4. D

    Select the integrated “Let’s Encrypt” option in Azure App Service and API Management to automatically enforce TLS 1.2 for both services without uploading any custom certificates.

Show answer and explanation

Correct answers: A, B

Explanation

To correctly implement TLS for an Azure App Service and an Azure API Management instance, you must configure custom domains with valid SSL certificates and ensure that the minimum TLS version is set to 1.2 or higher in both services. This includes uploading a valid SSL certificate to Azure App Service and binding a custom certificate to the custom domain in the API Management gateway. For more details, refer to Azure documentation on 'Configure TLS mutual authentication on Azure App Service' and 'Configure custom domains in Azure API Management.'

  • A. Correct.

    Correct. Uploading a valid SSL certificate for the custom domain and setting the minimum TLS version to 1.2 in Azure App Service ensures secure connections. This follows Microsoft’s best practice to only allow TLS 1.2 or higher.

  • B. Correct.

    Correct. In API Management, you must configure a custom domain for the gateway endpoint and provide a valid, trusted certificate for TLS. This step ensures inbound requests are protected using TLS 1.2 or above.

  • C. Incorrect.

    Incorrect. Enabling TLS 1.0 is not recommended. Microsoft recommends enforcing TLS 1.2 or higher to enhance security and avoid known vulnerabilities in older protocols.

  • D. Incorrect.

    Incorrect. While Let’s Encrypt can provide free certificates, it does not automatically enforce TLS 1.2 for both services without any configuration. You would still need to configure the custom domain and apply the correct TLS settings in each service.

Timed practice exam

Take a AZ-500 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam