You create a storage account and will add 10 blob containers. For one container you need to use a different key for encrypting data at rest. What must you do before creating that container?
Choose an answer
Tap an option to check your answer.
Correct answer: Create an encryption scope..
Why this is the answer
To use a different encryption key for a specific blob container within a storage account, you must first create an encryption scope. An encryption scope allows you to specify a separate encryption key (either a Microsoft-managed key or a customer-managed key) for data at rest at the container or blob level, overriding the default encryption key for the storage account. After creating the encryption scope, you can assign it to the desired container. Generating a shared access signature (SAS) is for granting limited access to resources, not for managing encryption keys. Modifying the minimum TLS version relates to security protocols for data in transit, not encryption at rest. Rotating access keys refreshes the storage account's primary and secondary access keys, but doesn't allow for per-container key management.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed