Microsoft Certified: Azure Security Engineer AssociateSecure data and applicationsEasy

A healthcare organization is migrating a legacy on-premises application to Azure App Service. The application uses a custom domain name and requires HTTP Strict Transport Security (HSTS) to enforce secure communication with clients. Which of the following is the most efficient way to enable HSTS for the Azure App Service application?

  1. AImplement an Azure Front Door instance and configure HSTS there.
  2. BEnable HSTS directly within the Azure App Service configuration blade.
  3. CConfigure a web.config transformation to include the HSTS header.
  4. DModify the application code to add the HSTS header to all responses.
Show answer & explanation

Correct answer: B. Enable HSTS directly within the Azure App Service configuration blade.

Azure App Service provides a direct setting in its configuration to enable HSTS, which is the most straightforward and efficient method compared to code changes or web.config edits.

Why the other options are wrong

  • A. Azure Front Door can enforce HSTS, but it's an additional service and an overkill if the application doesn't require other CDN or WAF features.
  • C. While possible, modifying web.config is less efficient and more prone to errors than using a built-in platform feature.
  • D. Modifying application code adds complexity, requires redeployment, and is not the most efficient way when a platform-level setting exists.

HTTP Strict Transport Security (HSTS)

A web security policy mechanism that helps to protect websites against protocol downgrade attacks and cookie hijacking by forcing web browsers to interact with it only using secure HTTPS connections.

  • Browser remembers to only use HTTPS for a specified duration.
  • Prevents HTTP-to-HTTPS downgrade attacks.
  • Set via a 'Strict-Transport-Security' HTTP response header.

Memory trick: App Service offers built-in security for simple enforcement.

More Secure data and applications questions