Encrypt Azure SQL Data at Rest, In Transit, and In Use — Always Encrypted + TDE + TLS
You are designing a secure data solution for a financial application. The data must be encrypted at rest, in transit, and in use. You choose Azure SQL Database. Which combination of features should you implement?
⚠ Common exam trap
Candidates often confuse Dynamic Data Masking with encryption, but masking only hides data from unauthorized users at query time while the underlying data remains unencrypted, failing the 'encrypted in use' requirement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Transparent Data Encryption, enforce TLS, and Always Encrypted
It addresses all three encryption states required by the scenario: Transparent Data Encryption (TDE) encrypts data at rest, enforcing TLS secures data in transit, and Always Encrypted protects data in use by keeping encryption keys client-side, ensuring plaintext data never appears in the database engine.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Transparent Data Encryption, enforce TLS, and Always Encrypted
Why this is correct
Transparent Data Encryption (TDE) encrypts database files, backups, and transaction logs at rest, ensuring stored data is unreadable without the database encryption key. Enforcing TLS 1.2+ protects data in transit between the application and Azure SQL, preventing man-in-the-middle interception. Always Encrypted encrypts sensitive columns client-side so the SQL engine never sees plaintext values, covering the data-in-use state during query processing. Together they comprehensively protect data at rest, in transit, and in use.
- ✗
Azure Information Protection, Dynamic Data Masking, and column-level security
Why it's wrong here
Azure Information Protection (AIP) is a classification and labeling service, not a native Azure SQL Database encryption feature, so it cannot protect SQL columns or query processing. Dynamic Data Masking (DDM) only obscures values in query results for unauthorized users, while the underlying data remains fully present and unencrypted in storage. Column-level security restricts which principals can SELECT specific columns but does not transform the data at all. This combination lacks true encryption for data at rest, in transit, or in use, leaving the data exposed to privileged database users.
- ✗
Always Encrypted, Microsoft Entra ID authentication, and Azure Information Protection
Why it's wrong here
Always Encrypted provides strong client-side column encryption, and Microsoft Entra ID authentication improves identity management, but the combination omits Transparent Data Encryption to protect database files and backups at rest. Azure Information Protection is not natively integrated with Azure SQL Database, so it adds no data-plane protection for the database service. Enforced TLS is also missing, leaving the network channel between the client and database potentially susceptible to interception. Therefore, this set fails to deliver comprehensive encryption coverage across all data states and includes a non-integrated control.
- ✗
Transparent Data Encryption, Dynamic Data Masking, and Microsoft Entra ID authentication
Why it's wrong here
Transparent Data Encryption adequately covers data at rest, and Microsoft Entra ID authentication strengthens access control, but Dynamic Data Masking (DDM) does not encrypt data in use or at rest—it merely redacts results for non-privileged users at query time. This option also omits enforced TLS, so data in transit between the application and database could be exposed to network eavesdropping. Without Always Encrypted, sensitive column values remain visible in plaintext to the SQL database engine and any user with elevated permissions. Thus, it leaves both the in-transit and in-use states without true encryption.
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.