Microsoft Azure Security Engineer Associate AZ-500 Practice Question

You are securing an Azure general-purpose v2 storage account that uses Microsoft-managed keys and is replicated with zone-redundant storage (ZRS). The security team has asked that every object written to the account be protected by two independent encryption layers while it is stored in Azure. Which action should you take to meet the requirement with the least administrative effort?

  • Migrate the data to a newly created Premium block blob account configured for encryption scopes.

  • Turn on Infrastructure encryption for the storage account.

  • Switch the account to customer-managed keys stored in Azure Key Vault and enable automatic key rotation.

  • Enable client-side encryption in all applications that write data to the account.

Microsoft Azure Security Engineer Associate AZ-500
Secure compute, storage, and databases
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot