AZ-500 Secure compute, storage, and databases Practice Question
Network Topology
Refer to the exhibit. You are analyzing the Always Encrypted configuration for an Azure SQL Database. The SSN column uses randomized encryption, and the CreditCard column uses deterministic encryption. Which statement is true regarding querying these columns?
⚠ Common exam trap
Test-takers frequently assume randomized encryption still supports equality searches because it is still 'encryption,' but the key distinction is that deterministic encryption is the only mode that allows server-side equality comparisons.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Only the CreditCard column supports equality searches.
Deterministic encryption always generates the same ciphertext for a given plaintext, enabling equality comparisons and point lookups. Randomized encryption produces different ciphertexts each time, preventing any equality or pattern-matching operations. Therefore, only the CreditCard column (deterministic) supports equality searches.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Both columns support equality searches.
Why it's wrong here
This statement is incorrect because it conflates the two encryption types used by Always Encrypted. Deterministic encryption, used for the CreditCard column, generates identical ciphertext for the same plaintext and therefore permits equality searches, but randomized encryption, used for SSN, produces different ciphertext every time and prevents equality and point lookup operations. Since both columns are not equally searchable, the claim fails.
- ✓
Only the CreditCard column supports equality searches.
Why this is correct
Correct. The CreditCard column uses deterministic encryption, which with the same plaintext and column encryption key always yields the same ciphertext, enabling SQL Server to perform equality comparisons and exact-match point lookups directly on the encrypted column. SSN, by contrast, uses randomized encryption, so the same value encrypts differently each time and cannot be compared for equality without client-side decryption. Therefore only CreditCard supports equality searches.
- ✗
Both columns support pattern matching with LIKE.
Why it's wrong here
Incorrect because Always Encrypted does not support LIKE pattern matching for either deterministic or randomized encryption. The server operates on opaque ciphertext; the client-side driver encrypts whole values, and there is no homomorphic or tokenization feature that would let SQL Server evaluate wildcards or substrings without first decrypting each row. Consequently, neither column in this configuration can use LIKE.
- ✗
Only the SSN column supports point lookups.
Why it's wrong here
This option misidentifies which column can perform point lookups. SSN is encrypted with randomized encryption, which yields non-deterministic ciphertext and explicitly disallows equality and point lookup queries, while the deterministic CreditCard column does allow exact-match point lookups. Thus the column that supports point lookups is CreditCard, not SSN, making the statement false.
Go deeper
Related to this question
About these practice questions
One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.