Microsoft Azure Security Engineer Associate AZ-500 Practice Question
You run a production web application on Azure App Service. A recent penetration test shows that the app still accepts TLS 1.0 and TLS 1.1 connections. The security team mandates that the site must allow only TLS 1.2 or later, and no code changes or downtime are acceptable. Which action should you take to meet the requirement?
Place the app behind an Azure Application Gateway configured with a custom TLS policy that disables TLS 1.0 and TLS 1.1.
Upload a new server certificate that explicitly supports only TLS 1.2 cipher suites.
In the App Service TLS/SSL settings, change the Minimum TLS Version setting to 1.2.
Add a rewrite rule in web.config that redirects all HTTP and TLS 1.0/1.1 traffic to HTTPS with TLS 1.2.
Azure App Service lets you restrict the accepted TLS protocol versions at the platform level. In the TLS/SSL settings blade (or through the site configuration property "minTlsVersion") you can set the Minimum TLS Version to 1.2. The platform then terminates any connection using TLS 1.0 or 1.1 before it reaches the application, so no code changes are required and traffic continues to flow uninterrupted. Uploading a new certificate does not influence the protocol version that clients can negotiate, web.config rules only affect redirects and cannot disable older TLS handshakes, and inserting an Application Gateway is unnecessary extra infrastructure when the App Service platform natively enforces the policy.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is TLS and why is TLS 1.2 preferred?
Open an interactive chat with Bash
How can you configure the Minimum TLS Version in Azure App Service?
Open an interactive chat with Bash
What is the difference between TLS enforcement provided by Azure App Service and Azure Application Gateway?
Open an interactive chat with Bash
Microsoft Azure Security Engineer Associate AZ-500
Secure networking
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .