AZ-500 Secure compute, storage, and databases Practice Question
A company uses Azure SQL Database for a critical application. Security policy requires that all client connections use at least TLS 1.2 encryption and that connections not meeting this requirement are rejected. Which configuration should they implement on the Azure SQL Server?
⚠ Common exam trap
Many exam-takers confuse encryption in transit (TLS) with encryption at rest (TDE) or network access controls (firewall rules), leading them to select options that address different security layers rather than the specific requirement to enforce a minimum TLS version.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Set the 'Minimum TLS version' on the SQL server
Azure SQL Server allows you to enforce a minimum TLS version for all client connections. By setting the 'Minimum TLS version' to 1.2, the server will reject any connection attempt using TLS 1.0 or 1.1, ensuring compliance with the security policy that requires at least TLS 1.2 encryption.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure firewall rules to allow only trusted IP addresses
Why it's wrong here
Configure firewall rules to allow only trusted IP addresses controls which source IPs can reach the Azure SQL Database logical server, using the server-level and database-level firewall settings. However, firewall rules operate at the network layer and do not inspect or enforce any TLS protocol version; a client from an allowed IP can still connect using TLS 1.0 or 1.1 unless a separate server-level TLS policy is set. Thus, while useful for limiting access to known hosts, it does not satisfy a requirement that all connections use at least TLS 1.2.
- ✗
Enable Transparent Data Encryption (TDE)
Why it's wrong here
Transparent Data Encryption (TDE) performs real-time encryption and decryption of database data files, log files, and backups at rest, protecting against physical theft of storage media or offline file access. TDE does not affect the client-to-server network connection: the encrypted data is transparently decrypted by the storage engine before being sent to the application, so it has no influence on whether the wire protocol uses TLS 1.2 or an older, less secure version. Enabling TDE is therefore an at-rest protection control, not a transport encryption policy.
- ✓
Set the 'Minimum TLS version' on the SQL server
Why this is correct
Setting the 'Minimum TLS version' on the Azure SQL Server enforces that every inbound client connection must negotiate at least TLS 1.2 at handshake time; if a client attempts to connect using TLS 1.0 or 1.1, the server rejects the connection entirely. This server-side enforcement is applied by the Azure SQL Gateway before any authentication or data exchange occurs, making it the correct control to ensure all traffic between the application and database is encrypted with a modern protocol version. The setting can be configured as 1.2 (or higher if supported) and is a hard policy, unlike client-side connection string options which a user could omit.
- ✗
Enable Advanced Threat Protection (ATP)
Why it's wrong here
Advanced Threat Protection (ATP) for Azure SQL Database, now part of Microsoft Defender for SQL, uses behavioral analytics and machine learning to generate security alerts for suspicious activities such as SQL injection, brute-force login attempts, anomalous access patterns, and potentially harmful queries. ATP is a detective and alerting control that surfaces threats after or during an attack, but it does not alter the TLS negotiation process or block clients based on protocol version. Therefore, ATP can help identify attacks over a TLS 1.2 connection but cannot enforce that only TLS 1.2+ connections are established, so it does not meet the stated requirement.
Go deeper
Related to this question
About these practice questions
This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.