Which two security configurations should you apply to an Azure SQL Database to meet a requirement for data protection at rest and in transit?
Use Always Encrypted for sensitive columns: Correct. It encrypts sensitive data both at rest and in transit by keeping encryption keys on the client side.
Why this answer
Option B (Always Encrypted for sensitive columns) is correct because Always Encrypted protects sensitive data both at rest and in transit by keeping data encrypted on the client side, so the database engine never sees plaintext — the column encryption keys are never exposed to Azure SQL Database. Option C (Transparent Data Encryption, TDE) is correct because TDE performs real-time encryption and decryption of the database, backups, and transaction log files at rest using a symmetric database encryption key protected by a certificate stored in Azure Key Vault or the service-managed key store, satisfying the data-at-rest requirement. Option A (Microsoft Defender for Azure SQL) is not correct here because it is a threat detection and vulnerability assessment service, not a data encryption mechanism for protecting data at rest or in transit.
Option D (firewall rules to allow only trusted IP addresses) is not correct because it is network access control, not encryption of data at rest or in transit. Option E (Azure SQL Auditing) is not correct because auditing tracks and logs database events for compliance and forensic purposes, but it does not encrypt or protect the data itself.
Exam trap
The trap here is that candidates often confuse Transparent Data Encryption (TDE) with protecting data in transit, but TDE only encrypts data at rest (the database files and backups), not data moving between the client and server.