AZ-500 Secure compute, storage, and databases Practice Question
A company uses Azure SQL Database for a critical application. Security policy requires that all client connections to the database use at least TLS 1.2 encryption. What configuration change must be made to enforce this requirement?
⚠ Common exam trap
Many exam-takers confuse encryption at rest (TDE) or column-level encryption (Always Encrypted) with encryption in transit, leading them to select options that do not enforce the TLS protocol version.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure the minimum TLS version in the SQL server's settings.
To enforce that all client connections to Azure SQL Database use at least TLS 1.2, you must configure the minimum TLS version at the SQL server level. This setting overrides the default behavior, which allows older, less secure TLS versions, and ensures that any connection attempt using TLS 1.0 or 1.1 is rejected. The configuration is made in the Azure portal under the SQL server's 'Connectivity' settings or via the 'Minimal TLS Version' property in ARM templates or PowerShell.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Configure the minimum TLS version in the SQL server's settings.
Why this is correct
Configuring the minimum TLS version at the Azure SQL logical server level directly enforces the encryption-protocol policy for all incoming client connections. When set to 1.2, the server rejects any TLS handshake attempt using 1.0 or 1.1, ensuring only modern, secure transport is used. This is the specific control that guarantees data is encrypted in transit between clients and the database.
- ✗
Enable Transparent Data Encryption (TDE).
Why it's wrong here
Transparent Data Encryption encrypts the database files, backup files, and transaction logs at rest using a database encryption key protected by a server certificate or asymmetric key. It does not apply to network traffic; data is decrypted when read into memory and can be transmitted in plaintext over the wire if TLS is not configured. Enabling TDE therefore does nothing to enforce a minimum TLS version for client connections.
- ✗
Update the server firewall rules to allow only specific IP addresses.
Why it's wrong here
Firewall rules at the Azure SQL server level restrict connections to a specified list of source IP addresses or IP ranges. They operate as an access control mechanism, blocking connections from unauthorized hosts, but they have no impact on the encryption protocol or TLS version used after a connection is allowed. A permitted client could still connect using TLS 1.0 or even no encryption, so firewall rules cannot enforce the required policy.
- ✗
Implement Always Encrypted for all sensitive columns.
Why it's wrong here
Always Encrypted is a client-side encryption feature that ensures sensitive columns are stored as ciphertext and the SQL server never sees the plaintext values, protecting data from being exposed to high-privilege database administrators. However, it only encrypts the designated columns; the rest of the query traffic, including any non-encrypted metadata or other data, is still subject to the normal connection channel. Always Encrypted does not validate or enforce the TLS version used between the client and server, so it cannot serve as the minimum TLS enforcement mechanism.
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.