A security audit finds that Terraform state files stored in Azure Blob Storage contain sensitive data in plaintext. What is the recommended mitigation?
-
A
Encrypt state files manually before uploading
-
B
Enable Azure Storage encryption with customer-managed keys and restrict access via RBAC
-
C
Move state storage to a local backend
-
D
Use terraform state rm to remove sensitive resources from state