Courseiva

Encrypt Azure SQL Data at Rest, In Transit, and In Use — Always Encrypted + TDE + TLS

You are designing a secure data solution for a financial application. The data must be encrypted at rest, in transit, and in use. You choose Azure SQL Database. Which combination of features should you implement?

⚠ Common exam trap

Candidates often confuse Dynamic Data Masking with encryption, but masking only hides data from unauthorized users at query time while the underlying data remains unencrypted, failing the 'encrypted in use' requirement.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Transparent Data Encryption, enforce TLS, and Always Encrypted

It addresses all three encryption states required by the scenario: Transparent Data Encryption (TDE) encrypts data at rest, enforcing TLS secures data in transit, and Always Encrypted protects data in use by keeping encryption keys client-side, ensuring plaintext data never appears in the database engine.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Transparent Data Encryption, enforce TLS, and Always Encrypted

    Why this is correct

    Transparent Data Encryption (TDE) encrypts database files, backups, and transaction logs at rest, ensuring stored data is unreadable without the database encryption key. Enforcing TLS 1.2+ protects data in transit between the application and Azure SQL, preventing man-in-the-middle interception. Always Encrypted encrypts sensitive columns client-side so the SQL engine never sees plaintext values, covering the data-in-use state during query processing. Together they comprehensively protect data at rest, in transit, and in use.

  • ✗

    Azure Information Protection, Dynamic Data Masking, and column-level security

    Why it's wrong here

    Azure Information Protection (AIP) is a classification and labeling service, not a native Azure SQL Database encryption feature, so it cannot protect SQL columns or query processing. Dynamic Data Masking (DDM) only obscures values in query results for unauthorized users, while the underlying data remains fully present and unencrypted in storage. Column-level security restricts which principals can SELECT specific columns but does not transform the data at all. This combination lacks true encryption for data at rest, in transit, or in use, leaving the data exposed to privileged database users.

  • ✗

    Always Encrypted, Microsoft Entra ID authentication, and Azure Information Protection

    Why it's wrong here

    Always Encrypted provides strong client-side column encryption, and Microsoft Entra ID authentication improves identity management, but the combination omits Transparent Data Encryption to protect database files and backups at rest. Azure Information Protection is not natively integrated with Azure SQL Database, so it adds no data-plane protection for the database service. Enforced TLS is also missing, leaving the network channel between the client and database potentially susceptible to interception. Therefore, this set fails to deliver comprehensive encryption coverage across all data states and includes a non-integrated control.

  • ✗

    Transparent Data Encryption, Dynamic Data Masking, and Microsoft Entra ID authentication

    Why it's wrong here

    Transparent Data Encryption adequately covers data at rest, and Microsoft Entra ID authentication strengthens access control, but Dynamic Data Masking (DDM) does not encrypt data in use or at rest—it merely redacts results for non-privileged users at query time. This option also omits enforced TLS, so data in transit between the application and database could be exposed to network eavesdropping. Without Always Encrypted, sensitive column values remain visible in plaintext to the SQL database engine and any user with elevated permissions. Thus, it leaves both the in-transit and in-use states without true encryption.

About these practice questions

Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.