Courseiva

CCNA Secure Compute Storage Db Questions

75 of 137 questions · Page 1/2 · Secure Compute Storage Db topic · Answers revealed

1
Multi-Selecteasy

You need to secure an Azure Storage account that will host sensitive data. Which TWO configurations should you implement?

Select 2 answers
A.Generate a shared access signature (SAS)
B.Enable 'Secure transfer required'
C.Allow public network access from all networks
D.Enable Azure Files
E.Configure a private endpoint
AnswersB, E

Enabling 'Secure transfer required' enforces HTTPS by rejecting all requests made over HTTP, ensuring that every interaction with the storage account is encrypted with TLS. This is a fundamental security baseline that protects data in transit from interception and man-in-the-middle attacks. It is a mandatory control for sensitive data and works in conjunction with private endpoints to guarantee end-to-end encryption.

Why this answer

Option B is correct because enabling 'Secure transfer required' on the storage account enforces HTTPS/TLS for all requests to the storage endpoints, rejecting any HTTP traffic so sensitive data is never transmitted in cleartext. Option E is correct because configuring a private endpoint assigns the storage account a private IP address inside your virtual network via Azure Private Link, removing exposure to the public internet and letting access flow only over the Microsoft backbone network. Option A is not correct here because a SAS is a delegated, time-limited access token for granting scoped permissions to clients, not a baseline network or transport security configuration for the account.

Option C is not correct because allowing public network access from all networks does the opposite of securing the account, exposing it to the internet. Option D is not correct because enabling Azure Files simply turns on the SMB/NFS file share service and does not itself harden or restrict access to the storage account.

2
MCQhard

A company uses Azure SQL Database with Transparent Data Encryption (TDE) and a customer-managed key stored in Azure Key Vault. The Key Vault is configured with a firewall that denies all public access. The SQL server must be able to access the key. What additional configuration is necessary?

A.Enable trusted Microsoft services on the Key Vault firewall
B.Create a private endpoint for Key Vault
C.Assign the SQL server's managed identity to the Key Vault
D.Configure a service endpoint on the SQL server
AnswerA

Enabling “Allow trusted Microsoft services to bypass this firewall” on the Key Vault is the correct fix because Azure SQL Database’s TDE key fetches originate from Microsoft’s PaaS infrastructure and, with this setting, those requests are exempted from the Key Vault firewall even when all public network access is otherwise blocked. This setting must be combined with the SQL server’s managed identity being granted the required key permissions, but without it, firewall rules alone would continue to reject the TDE key-wrap and unwrap calls.

Why this answer

When Azure Key Vault's firewall denies all public access, enabling 'Allow trusted Microsoft services' is necessary because Azure SQL Database's TDE key retrieval is considered a trusted service operation. This setting bypasses the firewall for specific Azure services like SQL Database that are authenticated and authorized to access the vault, without requiring a private endpoint or service endpoint.

Exam trap

The trap here is that candidates often confuse the authentication/authorization step (assigning managed identity) with the network connectivity step (firewall bypass), assuming that granting permissions alone is sufficient when the Key Vault firewall is blocking all traffic.

How to eliminate wrong answers

Option B is wrong because creating a private endpoint for Key Vault would provide private connectivity from a virtual network, but the SQL server is a platform-as-a-service resource that does not reside in a VNet by default; while possible, it is not the simplest or required configuration for TDE key access when the firewall is enabled. Option C is wrong because assigning the SQL server's managed identity to Key Vault is necessary for authentication and authorization (to grant the SQL server permissions to the key), but it does not bypass the Key Vault firewall; the firewall must still allow the request. Option D is wrong because configuring a service endpoint on the SQL server is not applicable; service endpoints are used for VNet integration, and Azure SQL Database does not have a service endpoint that directly controls Key Vault access.

3
Multi-Selectmedium

You are designing security for an Azure SQL Database that will store personally identifiable information (PII). The database will be accessed by multiple applications, some of which are legacy and cannot use Azure AD authentication. Your requirements include: encrypting data at rest, encrypting data in transit, and dynamically masking PII columns for non-privileged users. Which THREE features should you implement?

Select 3 answers
A.Configure Dynamic Data Masking (DDM) for the PII columns.
B.Implement Always Encrypted for the PII columns.
C.Set the 'Minimum TLS Version' to 1.2 on the Azure SQL Server.
D.Enable Transparent Data Encryption (TDE) for the Azure SQL Database.
E.Apply Azure Information Protection labels to the database.
AnswersA, C, D

Dynamic Data Masking (DDM) hides sensitive PII from non-privileged users by applying masking rules (e.g., email or credit-card patterns) at query runtime without altering the underlying data. It is a server/database-level security feature that can be enabled on specific columns, and privileged users can still see the full values. DDM does not protect data in transit or at rest—it only addresses unauthorized viewing by presenting masked values to certain principals.

Why this answer

(Dynamic Data Masking) masks PII columns for non-privileged users. Option C (Minimum TLS Version 1.2) ensures data in transit is encrypted. Option D (Transparent Data Encryption) encrypts data at rest.

Option B (Always Encrypted) is client-side and requires client support, not suitable for legacy apps. Option E (Azure Information Protection) is not a database security feature for this scenario.

4
MCQhard

A company uses Azure Disk Encryption (ADE) on Windows virtual machines. They use a key encryption key (KEK) stored in Azure Key Vault to wrap the disk encryption key. The security policy requires that the KEK be automatically rotated every 90 days. They need to ensure that after rotation, the OS and data disks of running VMs automatically get re-wrapped with the new KEK version. Which configuration should they implement?

A.Enable soft-delete and purge protection on the Key Vault.
B.Use Key Vault key auto-rotation with a 90-day rotation period, and configure the disk encryption set to use the latest key version (empty string).
C.Create a new KEK every 90 days and modify the disk encryption set to point to the new key version.
D.Use Azure Policy to enforce automatic key rotation.
AnswerB

Key Vault key auto-rotation creates new key versions on schedule. By setting the key version to empty in the disk encryption set, the VMs automatically re-wrap their disks with the latest key version after rotation.

Why this answer

Azure Key Vault supports automatic key rotation with a configurable rotation period, and when a disk encryption set (DES) is configured with an empty string as the key version, it automatically uses the latest version of the KEK. This ensures that after the KEK is rotated every 90 days, the running VMs' OS and data disks are re-wrapped with the new KEK version without manual intervention or VM restart.

Exam trap

The trap here is that candidates may confuse Azure Policy (which enforces compliance) with actual key rotation and re-wrapping mechanisms, or mistakenly believe that manual key version updates in the DES are sufficient for automatic re-wrapping of running VMs.

How to eliminate wrong answers

Option A is wrong because enabling soft-delete and purge protection on the Key Vault is a data protection and recovery feature, not a mechanism for automatic key rotation or re-wrapping of disks. Option C is wrong because manually creating a new KEK every 90 days and updating the DES to point to the new key version is a manual process that does not meet the requirement for automatic rotation and re-wrapping. Option D is wrong because Azure Policy can enforce compliance rules but cannot directly trigger automatic key rotation or re-wrapping of disks; it is a governance tool, not a key lifecycle management feature.

5
MCQmedium

A company uses Azure SQL Database to store customer data, including credit card numbers. The security policy requires that database administrators (DBAs) must not be able to view the credit card numbers in plaintext. The column containing the credit card numbers must be encrypted at rest and in transit, and only a specific application (using a dedicated client library) should be able to decrypt the data. Which technology should they implement?

A.Transparent Data Encryption (TDE) with a customer-managed key stored in Azure Key Vault.
B.Dynamic Data Masking (DDM) for the credit card column.
C.Always Encrypted with a client-side encryption key stored in Azure Key Vault.
D.Row-Level Security (RLS) to restrict DBA access to the credit card column.
AnswerC

Correct. Always Encrypted encrypts the data on the client side, so the SQL Database never sees the plaintext. Only the client application with access to the encryption key can decrypt the data, preventing DBAs from viewing sensitive columns.

Why this answer

Always Encrypted ensures that sensitive data, such as credit card numbers, is encrypted on the client side before being sent to Azure SQL Database, and the encryption keys are never revealed to the database engine. This prevents DBAs or any server-side administrators from viewing the plaintext data, as decryption can only occur using the client-side encryption key stored in Azure Key Vault and accessed by the dedicated application library.

Exam trap

The trap here is that candidates often confuse Dynamic Data Masking (DDM) with encryption, not realizing that DDM only masks output and does not protect the underlying plaintext from privileged users or direct database access.

How to eliminate wrong answers

Option A is wrong because Transparent Data Encryption (TDE) encrypts data at rest but does not protect data from DBAs who have access to the database; the database engine can still decrypt the data in memory and in transit unless additional measures are taken, and it does not enforce client-side-only decryption. Option B is wrong because Dynamic Data Masking (DDM) only obfuscates data in query results for unauthorized users, but the underlying plaintext is still stored in the database and can be accessed by privileged users or through direct queries. Option D is wrong because Row-Level Security (RLS) restricts access to rows based on predicates but does not encrypt the data; DBAs with elevated permissions can bypass RLS or still view the plaintext column values.

6
MCQmedium

A company stores sensitive financial documents in Azure Blob Storage. The security team needs to maintain an immutable log of all changes to the blob content, including the previous versions and the identity of the user who made the changes, for forensic analysis. Which Azure Storage feature should they enable on the storage account to meet this requirement?

A.Azure Blob Storage soft delete.
B.Azure Blob Storage versioning.
C.Blob Storage change feed.
D.Azure Storage analytics logs.
AnswerC

Blob Storage change feed is the correct choice because it provides an append-only, immutable transaction log that captures every creation, update, and deletion of blobs in a storage account, ordered by blob modification time. Each change feed record includes the blob's ETag, content length, and a timestamp, but it does not natively capture user identity; however, by correlating change feed events with Azure Storage Analytics logs (which record the caller's user ID, IP address, and operation details), you can attribute each change to a specific principal. This enables a tamper-resistant, chronological audit trail that satisfies the requirement to show 'who' performed each action, something soft delete, versioning, or analytics logs alone cannot guarantee.

Why this answer

The Blob Storage change feed provides an immutable, append-only log of all changes (create, update, delete) to blobs and blob metadata, including the previous version and the identity of the user who made the change via the requestor's object ID. This meets the forensic requirement for a complete audit trail of blob content changes.

Exam trap

The trap here is that candidates often confuse versioning (which preserves previous versions for recovery) with the change feed (which provides an immutable audit log of changes), leading them to select versioning when the requirement explicitly calls for a forensic log with user identity.

How to eliminate wrong answers

Option A is wrong because soft delete only preserves deleted blobs for a retention period and does not log changes to existing blob content or track user identity. Option B is wrong because versioning maintains previous versions of blobs but does not provide a chronological log of changes with user identity; it is a point-in-time recovery feature, not an audit trail. Option D is wrong because Storage analytics logs (now deprecated in favor of Azure Monitor resource logs) capture storage service operations but are not immutable by default and do not include previous blob content or a guaranteed append-only log.

7
MCQmedium

A storage account contains legal evidence that must not be modified or deleted for seven years. Which feature should be configured?

A.Soft delete only
B.Lifecycle management to archive tier
C.Customer-managed keys
D.Immutable blob storage with a time-based retention policy
AnswerD

Immutable blob storage with a time-based retention policy enforces WORM (write once, read many) semantics, which prohibit any deletion or overwrite of blobs until the retention interval expires. This policy is a hard data-integrity control that meets legal preservation requirements by keeping evidence immutable and auditable. It is the direct, purpose-built Azure feature for ensuring legal evidence cannot be altered or removed.

Why this answer

Immutable blob storage with a time-based retention policy (WORM – Write Once, Read Many) is the correct choice because it enforces a strict seven-year retention period during which blobs cannot be modified or deleted, even by account administrators. This is achieved through a policy that locks the data at the storage level, ensuring compliance with legal hold requirements for evidence preservation.

Exam trap

The trap here is that candidates often confuse soft delete (which only protects against accidental deletion for a short period) with immutable storage (which enforces a hard, non-negotiable retention lock against both modification and deletion for a specified duration).

How to eliminate wrong answers

Option A is wrong because soft delete only provides protection against accidental deletion for a configurable retention period (default 7 days), but it does not prevent modifications or enforce a fixed seven-year legal hold; data can still be overwritten or deleted permanently after the soft-delete period expires. Option B is wrong because lifecycle management to the archive tier is designed for cost optimization by moving data to cooler storage tiers, not for preventing modification or deletion; data in the archive tier can still be deleted or overwritten by authorized users. Option C is wrong because customer-managed keys (CMK) control encryption at rest using Azure Key Vault, but they do not impose any retention or immutability constraints; data remains fully mutable and deletable regardless of key management.

8
MCQhard

You are deploying an Azure Storage account using an ARM template that includes a networkAcls section with defaultAction set to Deny. After deployment, you need to allow access from a specific public IP address. What should you do?

A.Create a private endpoint and assign it to the storage account.
B.Add an IP rule to the ipRules array with the public IP address.
C.Configure a service endpoint for the storage account.
D.Update the defaultAction to Allow and set ipRules to deny the IP.
AnswerB

IP rules allow specific public IPs to bypass the deny default.

Why this answer

The ARM template includes a `networkAcls` section with `defaultAction` set to `Deny`, which blocks all traffic by default. To allow access from a specific public IP address, you must add an IP rule to the `ipRules` array, specifying the public IP address in CIDR notation (e.g., "20.10.10.10/32"). This overrides the default deny for that specific IP, enabling access while keeping the storage account locked down from other public traffic.

Exam trap

The trap here is that candidates often confuse network ACLs with service endpoints or private endpoints, mistakenly thinking that service endpoints (Option C) or private endpoints (Option A) can be used to allow a specific public IP, when in fact they are designed for private network connectivity from Azure virtual networks.

How to eliminate wrong answers

Option A is wrong because creating a private endpoint assigns a private IP address from your virtual network to the storage account, which is used for private connectivity and does not allow access from a specific public IP address. Option C is wrong because configuring a service endpoint extends your virtual network identity to the storage account, allowing traffic from a subnet, not from a specific public IP address. Option D is wrong because updating `defaultAction` to `Allow` would permit all public traffic, which is overly permissive and defeats the purpose of restricting access to a single IP; setting `ipRules` to deny the IP would be redundant and ineffective since the default allow would override any deny rules.

9
MCQeasy

You are deploying a web application that stores user-uploaded files in Azure Blob Storage. You need to ensure that only authenticated users can upload files, and that uploaded files are automatically scanned for malware. What should you use?

A.Use Azure Event Grid to trigger a function for malware scanning
B.Enable Azure AD authentication for the storage account and enable Microsoft Defender for Storage
C.Configure Azure Firewall to allow only the web app's IP address
D.Use shared access signatures (SAS) with stored access policies
AnswerB

Enabling Azure AD authentication for the storage account replaces shared-key or SAS access with OAuth 2.0 tokens, allowing you to assign RBAC roles such as Storage Blob Data Contributor to individual users or service principals. This gives you per-user identity, conditional access, and audit logs for every upload. Microsoft Defender for Storage then continuously analyzes blob activity and scans files for malware using threat intelligence and hash reputation, alerting on detections and optionally applying high-confidence malware scans. Together these two controls address both identity and content security, which is exactly what the scenario requires.

Why this answer

Enabling Azure AD authentication for the storage account ensures that only authenticated users (via Azure AD) can upload files, while Microsoft Defender for Storage provides built-in malware scanning for uploaded blobs. This combination directly addresses both requirements without additional infrastructure.

Exam trap

The trap here is that candidates often choose Event Grid (Option A) thinking it handles both authentication and scanning, but it only triggers scanning after upload and does not enforce authentication, missing the core requirement.

How to eliminate wrong answers

Option A is wrong because Azure Event Grid triggers a function for malware scanning only after the file is uploaded, but it does not enforce authentication for the upload itself; it also adds latency and complexity. Option C is wrong because Azure Firewall restricts network access by IP address, but it does not authenticate individual users or scan files for malware. Option D is wrong because shared access signatures (SAS) with stored access policies provide delegated access but do not enforce per-user authentication via Azure AD, nor do they include malware scanning.

10
MCQhard

An AKS cluster needs to pull container images from a private Azure Container Registry (ACR). The security policy requires that the AKS cluster identity should not have direct access to the ACR; instead, a service principal with the AcrPull role should be used, with credentials stored as a Kubernetes secret. Which authentication method should be configured on the AKS cluster?

A.AKS managed identity
B.ACR admin account
C.Kubernetes pull secret using a service principal
D.Azure AD pod identity
AnswerC

To implement this, create a service principal with only the AcrPull role, use its app ID and password as the username and password fields, and store the base64-encoded Docker config in a Kubernetes secret of type `kubernetes.io/dockerconfigjson`. Reference that secret in a pod's `imagePullSecrets` so the kubelet uses it to authenticate only for the pods that declare it, limiting access to those specific workloads. This credential is scoped to the service principal and can be rotated or revoked independently without affecting the cluster's control-plane identity, making it the correct choice when the policy explicitly demands a service principal secret instead of an identity-based assignment.

Why this answer

The scenario explicitly requires that the AKS cluster identity not have direct access to ACR, and instead mandates using a service principal with AcrPull role whose credentials are stored as a Kubernetes secret. A Kubernetes pull secret of type 'docker-registry' stores the service principal's client ID and client secret, which kubelet uses to authenticate to ACR when pulling images. This method decouples the AKS cluster's managed identity from ACR access, satisfying the security policy.

Exam trap

The trap here is that candidates often confuse 'AKS managed identity' with the requirement for a service principal secret, mistakenly thinking managed identity is always the best practice, but the question explicitly prohibits direct cluster identity access to ACR.

How to eliminate wrong answers

Option A is wrong because AKS managed identity would grant the cluster's own identity direct access to ACR, which violates the policy that the cluster identity should not have direct access. Option B is wrong because the ACR admin account is a shared, static credential with full access to the registry, and it is not a service principal; it also bypasses the requirement to use a service principal with AcrPull role. Option D is wrong because Azure AD pod identity is used to assign Azure AD identities to pods for accessing Azure resources, but it does not store credentials as a Kubernetes secret; it relies on Azure AD authentication and would still involve the cluster identity or pod-level managed identities, not a service principal secret stored in the cluster.

11
Multi-Selectmedium

Which TWO actions should you take to ensure that an Azure Storage account is only accessible over HTTPS and that data in transit is encrypted?

Select 2 answers
A.Configure a custom domain with HTTPS enabled.
B.Set 'Secure transfer required' to Enabled.
C.Deploy Azure Firewall in front of the storage account.
D.Set the minimum TLS version to 1.2.
E.Use Azure Private Link to connect to the storage account.
AnswersB, D

Setting 'Secure transfer required' to Enabled instructs Azure Storage to reject any request that arrives over plain HTTP, returning an error such as 403 Forbidden for non-HTTPS attempts. This enforces that all data transmitted to or from blob, table, queue, and file endpoints must use TLS/HTTPS, regardless of whether the client uses the public endpoint, a custom domain, or a shared access signature. It is the primary control that makes encryption-in-transit mandatory for the storage account.

Why this answer

Enabling 'Secure transfer required' on an Azure Storage account rejects any HTTP requests and enforces HTTPS for all data in transit. Option D is correct because setting the minimum TLS version to 1.2 ensures that only clients using TLS 1.2 or higher can connect, which prevents downgrade attacks and enforces strong encryption for data in transit.

Exam trap

The trap here is that candidates often confuse 'Secure transfer required' with 'minimum TLS version' or think that Azure Firewall or Private Link alone can enforce encryption, but neither of those services actually enforces HTTPS or TLS for data in transit.

12
MCQmedium

You have an Azure Cosmos DB account with multiple containers. You need to ensure that only specific Azure AD identities can access the data and that all access is logged. What should you use?

A.Use primary keys for authentication and enable audit logging
B.Use Azure AD authentication and RBAC roles, and enable diagnostic logs
C.Configure managed identities for Azure resources and enable diagnostic logs
D.Configure an Azure Cosmos DB firewall and enable diagnostic logs
AnswerB

Azure Active Directory authentication with RBAC roles is the correct choice because it binds each request to a specific user or service principal, enabling fine-grained permissions through built-in roles such as Cosmos DB Built-in Data Reader and Contributor. Enabling diagnostic logs for the account captures both control-plane and data-plane operations, providing a comprehensive audit trail for who accessed which container, when, and from where. This combination delivers identity-based access control, least privilege, and auditing that the other options lack.

Why this answer

Azure AD authentication with RBAC roles allows you to restrict data access to specific Azure AD identities, and enabling diagnostic logs captures all data plane operations for auditing. This combination meets the requirements of identity-based access control and comprehensive logging, unlike primary keys which are shared secrets and do not support identity-level auditing.

Exam trap

The trap here is that candidates often confuse network-level controls (firewall) or shared keys with identity-based access control, overlooking that Azure AD authentication with RBAC is the only option that provides both identity-specific access and auditable logging.

How to eliminate wrong answers

Option A is wrong because primary keys are shared secrets that grant full access to all data in the account and cannot be scoped to specific Azure AD identities, nor do they provide per-identity audit logging. Option C is wrong because managed identities are used for authenticating Azure resources to Cosmos DB, not for restricting access to specific Azure AD identities; they still require RBAC roles and diagnostic logs to meet the logging requirement, but the option omits RBAC. Option D is wrong because a firewall only controls network-level access by IP address, not identity-based access control, and while diagnostic logs can be enabled, the firewall does not enforce Azure AD identity restrictions.

13
MCQmedium

Your organization uses Azure Storage to host sensitive financial data. You need to ensure that all access to the storage account is encrypted in transit and that access keys are rotated automatically every 90 days. You also need to prevent access from public IP addresses. Which combination of configurations should you implement?

A.Configure a network firewall rule to block all traffic, enable 'Secure transfer required', and rotate keys manually every 90 days
B.Enable 'Allow trusted Microsoft services', configure key rotation policy, and disable 'Allow storage account key access'
C.Enable 'Secure transfer required', configure key rotation policy, and disable 'Allow Blob public access'
D.Enable 'Secure transfer required', configure key rotation policy, and set 'Public network access' to 'Disabled'
AnswerD

This is the correct configuration because it addresses three independent layers of protection. 'Secure transfer required' forces all clients to use HTTPS and reject HTTP requests; the key rotation policy automatically rotates shared account keys within a defined period, limiting the lifetime of any leaked key; and 'Public network access: Disabled' blocks the storage account's public endpoint entirely, requiring connections to come through private endpoints or approved virtual network paths. Together these controls provide defense-in-depth for sensitive financial data.

Why this answer

Option D is correct because it directly satisfies all three requirements: enabling 'Secure transfer required' enforces HTTPS/TLS encryption in transit, configuring a key rotation policy automatically rotates the storage account access keys on a 90-day schedule, and setting 'Public network access' to 'Disabled' blocks access from public IP addresses (forcing private endpoint/private link access). The other options fall short: A relies on manual key rotation and a blanket firewall block rather than automatic rotation, B disables storage account key access (which conflicts with rotating access keys) and does not disable public network access, and C disables only anonymous blob public access, which does not prevent access from public IP addresses.

14
MCQhard

An Azure SQL Database contains salary data. Support analysts need to query employee records but must not see full salary values. Which feature is most appropriate when the application cannot be changed immediately?

A.Transparent Data Encryption
B.Dynamic data masking
C.Geo-replication
D.Accelerated database recovery
AnswerB

Dynamic Data Masking (DDM) is a column-level, query-time control that applies masking rules to results returned to non-privileged users, making salary values appear as partial, default, or random placeholders. Because the masking is applied dynamically without modifying the underlying data, analysts can still query the table and see non-sensitive columns while sensitive salary content is obscured. This precisely satisfies the need to let support analysts work with the database without exposing salary data.

Why this answer

Dynamic data masking (DDM) is the correct choice because it obfuscates sensitive data in query results without modifying the underlying database or requiring application changes. The support analysts can still query employee records, but the salary column is masked according to a defined masking rule (e.g., showing only the last four digits or replacing with zeros). This meets the requirement of preventing full salary exposure while the application remains unchanged.

Exam trap

The trap here is confusing data-at-rest encryption (TDE) with data-masking at query time—candidates often assume encryption alone prevents unauthorized viewing, but encryption does not affect what authorized users see when they run SELECT queries.

How to eliminate wrong answers

Option A is wrong because Transparent Data Encryption (TDE) encrypts data at rest on disk and in backups, but it does not control what users see when querying the database—authorized users still see full salary values. Option C is wrong because geo-replication provides disaster recovery by maintaining a readable secondary replica in a different region, but it does not restrict data visibility in query results. Option D is wrong because accelerated database recovery (ADR) improves transaction rollback speed and database availability after failures, but it has no effect on data masking or access control.

15
MCQhard

Your company is migrating a legacy on-premises application to Azure VMs. The application writes log files to a local folder. You need to collect these logs centrally for security analysis using Microsoft Sentinel. The application runs on Windows Server 2022 and is expected to generate about 50 GB of logs per day. The security team requires that logs be encrypted at rest and in transit, and that log collection has minimal latency. You set up Azure Monitor Agent (AMA) on the VM and configure a Data Collection Rule (DCR) to stream custom logs to a Log Analytics workspace. However, after 24 hours, no custom logs appear in the workspace. The AMA is reporting as healthy. You need to troubleshoot and resolve the issue. What is the most likely cause?

A.The DCR does not include the correct table name for the custom log, or the table does not exist in the Log Analytics workspace.
B.The custom log file path specified in the DCR is a local path, but AMA requires a network share for custom log collection.
C.The log file format is not JSON, but AMA only supports custom logs in JSON format.
D.The VM does not have local administrator privileges required for the AMA to read the log files.
AnswerA

The Data Collection Rule (DCR) must map the incoming stream to an existing table in the Log Analytics workspace, typically a custom table with a `_CL` suffix. The `tableName` specified in the `destinations` section must exactly match the table that was created, including case and suffix. The DCR does not automatically create the table, so if the name is misspelled or the table has not been provisioned, the ingestion pipeline silently drops the data.

Why this answer

The DCR must reference the custom log table created in the Log Analytics workspace; if the table name does not match or the table does not exist, logs will not be ingested. Option B: AMA can collect custom logs from a local file path; the path does not need to be a network share. Option C: The log file format is not limited to JSON; AMA can collect plain text logs with a defined pattern.

Option D: The agent does not require local admin privileges for custom log collection; it runs as Local System.

16
MCQmedium

A company uses Azure Key Vault to store secrets. They want to grant developers the ability to read secrets, but only for specific secret names (e.g., 'App--ConnectionString'). They also want to use Azure RBAC instead of the Key Vault access policy model. Which RBAC role should they assign, and at which scope?

A.Assign the 'Key Vault Secrets User' role at the secret scope
B.Assign the 'Key Vault Secrets User' role at the vault scope
C.Assign the 'Key Vault Reader' role at the secret scope
D.Assign the 'Key Vault Secrets Officer' role at the secret scope
AnswerA

The 'Key Vault Secrets User' role permits reading secret content. When scoped to an individual secret, it restricts access to that specific secret only. Azure RBAC supports data plane roles at the secret, key, or certificate level.

Why this answer

The 'Key Vault Secrets User' role, when assigned at the individual secret scope (e.g., /subscriptions/{sub}/resourceGroups/{rg}/providers/Microsoft.KeyVault/vaults/{vault}/secrets/{secretName}), grants read-only access to that specific secret. This satisfies the requirement to use Azure RBAC (instead of the legacy access policy model) and to limit developers to reading only secrets with a specific name, such as 'App--ConnectionString'.

Exam trap

The trap here is that candidates often assume RBAC roles can only be assigned at the vault scope, forgetting that Azure RBAC supports fine-grained scoping down to the individual secret level, which is essential for least-privilege access control.

How to eliminate wrong answers

Option B is wrong because assigning the 'Key Vault Secrets User' role at the vault scope would grant read access to all secrets in the vault, not just the specific secret name required. Option C is wrong because the 'Key Vault Reader' role only allows listing vaults and reading metadata (e.g., vault properties), not reading secret values; it does not include the 'Microsoft.KeyVault/vaults/secrets/read' action needed to retrieve secret content. Option D is wrong because the 'Key Vault Secrets Officer' role includes write and delete permissions (e.g., 'Microsoft.KeyVault/vaults/secrets/write' and 'delete'), which exceeds the required read-only access and violates the principle of least privilege.

17
MCQmedium

A company uses Azure SQL Database with Transparent Data Encryption (TDE) using a customer-managed key (CMK) stored in Azure Key Vault. The Key Vault has a firewall enabled that denies all public network access. The SQL server has a system-assigned managed identity assigned the 'Key Vault Crypto Service Encryption User' role. However, TDE operations are failing because the SQL server cannot access the Key Vault. What additional configuration is needed?

A.Enable the Key Vault firewall to allow trusted Microsoft services
B.Create a private endpoint for the SQL server to access the Key Vault
C.Enable public network access on the Key Vault
D.Assign the SQL server's managed identity the 'Reader' role on the Key Vault
AnswerA

Azure SQL Database TDE with customer-managed keys requires SQL to access Key Vault for key wrap and unwrap operations. The Key Vault firewall blocks public access, but the 'Allow trusted Microsoft services' exception lets Azure SQL's underlying service bypass the firewall for these cryptographic operations, using the SQL server's managed identity. This is the only network change needed while keeping public access blocked.

Why this answer

When Azure Key Vault has its firewall enabled to deny all public network access, it blocks all traffic, including requests from Azure SQL Database. By enabling the 'Allow trusted Microsoft services' exception, Azure Key Vault permits specific Azure platform services (like Azure SQL Database) to bypass the firewall, provided the service authenticates using a managed identity with appropriate permissions. This setting is essential for TDE with CMK because the SQL server's system-assigned managed identity must reach the Key Vault to unwrap the encryption key, even when public access is disabled.

Exam trap

The trap here is that candidates often assume a private endpoint is required for any cross-service communication when firewalls are involved, but Azure's 'Allow trusted Microsoft services' exception is a simpler, first-line configuration that enables necessary platform-level access without exposing the Key Vault to the internet.

How to eliminate wrong answers

Option B is wrong because creating a private endpoint for the SQL server to access the Key Vault would require the SQL server to initiate a connection through a private IP, but the SQL server itself does not support outbound private endpoints to Key Vault; private endpoints are configured on the Key Vault side, not the SQL server side, and the scenario already has the Key Vault firewall denying all public access, so a private endpoint on the Key Vault would be needed, but that is not listed as an option and would not resolve the immediate firewall block without the trusted services exception. Option C is wrong because enabling public network access on the Key Vault would defeat the security purpose of the firewall and is unnecessary; the trusted services exception allows the required access without exposing the Key Vault to the public internet. Option D is wrong because the 'Reader' role on the Key Vault only grants read access to the vault's metadata and secrets list, not the cryptographic permissions needed for TDE operations; the 'Key Vault Crypto Service Encryption User' role is already assigned and provides the necessary unwrap key permission, so adding 'Reader' is irrelevant.

18
MCQhard

A company has an Azure Storage account with infrastructure encryption enabled. They configure the storage account to use customer-managed keys (CMK) stored in Azure Key Vault for encryption at rest. Despite this configuration, newly uploaded blobs are still encrypted with Microsoft-managed keys. What is the most likely cause?

A.The storage account was created before infrastructure encryption was generally available
B.The customer-managed key in Key Vault is disabled or expired
C.The storage account's encryption type is set to Microsoft-managed keys
D.The blob container has a policy that overrides the encryption setting
AnswerC

The storage account's encryption type is the explicit control that determines which key type is used for Azure Storage encryption. If the encryption type is set to 'Microsoft-managed keys', all blob data is encrypted with Microsoft-managed keys regardless of any customer-managed key configuration that may also exist in the account. To use a customer-managed key, the account must be created or updated with the encryption type set to 'Customer-managed keys' and a key must be specified in Key Vault. Since the blobs are encrypted with Microsoft-managed keys, the encryption type must be the one controlling this behavior.

Why this answer

The storage account's encryption type must be explicitly set to 'Customer-managed keys' to use CMK from Azure Key Vault. If the encryption type remains at the default 'Microsoft-managed keys', newly uploaded blobs will continue to be encrypted with Microsoft-managed keys regardless of the CMK configuration in Key Vault. Infrastructure encryption is a separate feature that encrypts data at the hardware level and does not affect the key management type.

Exam trap

The trap here is that candidates often assume that simply configuring a customer-managed key in Key Vault automatically changes the storage account's encryption type, but Azure requires an explicit configuration step to switch the encryption type from 'Microsoft-managed keys' to 'Customer-managed keys'.

How to eliminate wrong answers

Option A is wrong because infrastructure encryption is a separate feature that encrypts data at the storage infrastructure level (before the data is written to disk) and does not influence the choice between Microsoft-managed and customer-managed keys; the storage account's creation date does not prevent CMK from being applied. Option B is wrong because if the customer-managed key in Key Vault is disabled or expired, the storage account would fail to encrypt new blobs with CMK and would likely throw an error or fall back to Microsoft-managed keys only if the account is configured to allow that fallback, but the question states the blobs are still encrypted with Microsoft-managed keys without error, indicating the encryption type was never set to CMK. Option D is wrong because blob containers do not have policies that can override the storage account's encryption setting; encryption at rest is configured at the storage account level and applies to all blobs uniformly.

19
Multi-Selecthard

Which TWO components are required to enable Azure Disk Encryption for Windows VMs using Azure Key Vault? (Choose two.)

Select 2 answers
A.Azure Key Vault with an access policy granting permissions to the Azure Disk Encryption service
B.A key encryption key (KEK) in Azure Key Vault
C.A Recovery Services vault
D.A storage account to store the encryption logs
E.The Azure Disk Encryption extension installed on the VM
AnswersA, E

Azure Disk Encryption needs the Key Vault access policy that grants the Azure Disk Encryption service principal the wrapKey, unwrapKey and get permissions, so it can read and write the key encryption keys and secrets.

Why this answer

Option A is correct because Azure Disk Encryption (ADE) for Windows VMs requires an Azure Key Vault that holds the BitLocker encryption keys (BEKs) and secrets, and the vault must have an access policy that grants the Azure Disk Encryption service principal the required permissions (key permissions such as wrapKey/unwrapKey and secret permissions such as get/set) so the ADE extension can read and write the secrets. Option E is correct because ADE is delivered as a VM extension (the AzureDiskEncryption extension for Windows, or AzureDiskEncryptionForLinux for Linux) that must be installed on the VM to perform the actual encryption of the OS and data disks. Option B is not required: a key encryption key (KEK) is an optional second layer of key protection used to wrap the BitLocker keys, not a mandatory component.

Option C is not required: a Recovery Services vault is used for Azure Backup, not for ADE key storage. Option D is not required: ADE does not need a storage account to store encryption logs; diagnostic/audit data is handled through Azure Monitor and Key Vault logging.

Exam trap

The trap is that candidates often assume a KEK is mandatory because it is commonly used, but Azure Disk Encryption works without it. Additionally, candidates may confuse the requirements with those of Azure Backup, which does require a Recovery Services vault.

20
MCQmedium

A company enables Azure Disk Encryption (ADE) on Windows virtual machines using a key encryption key (KEK) stored in Azure Key Vault. They want the KEK to be automatically rotated every 30 days to meet compliance requirements. Which Azure Key Vault feature should they enable?

A.Key rotation policy
B.Key expiration date
C.Soft-delete
D.Purge protection
AnswerA

Azure Key Vault's key rotation policy enables automatic generation of a new key version at a specified interval, such as every 30 days, without administrator intervention. For Azure Disk Encryption, this rotation re-wraps the BitLocker key encryption key (KEK) used to encrypt the disk encryption key (DEK), ensuring that the underlying data remains encrypted while the key material is refreshed. This is the correct option because it satisfies the requirement for automatic, recurring key rotation as opposed to a one-time action.

Why this answer

A key rotation policy in Azure Key Vault allows you to define automatic rotation rules for keys, including a rotation interval (e.g., every 30 days) and a rotation time window. This feature ensures that the KEK is automatically replaced with a new key version at the specified interval without manual intervention, meeting compliance requirements for periodic key rotation.

Exam trap

The trap here is that candidates often confuse key expiration (which only invalidates a key) with key rotation (which creates a new version and keeps the old one valid for a time), leading them to select 'Key expiration date' instead of 'Key rotation policy'.

How to eliminate wrong answers

Option B is wrong because a key expiration date sets a fixed end-of-life date for a key, after which it becomes invalid, but it does not automatically rotate the key; it only marks it as expired. Option C is wrong because soft-delete is a recovery feature that retains deleted keys for a configurable retention period, but it does not perform any automatic rotation of keys. Option D is wrong because purge protection prevents permanent deletion of soft-deleted keys, but it has no role in key rotation or lifecycle management.

21
MCQeasy

A company plans to migrate on-premises SQL Server databases to Azure SQL Managed Instance. The security team requires that all data at rest be encrypted using customer-managed keys stored in Azure Key Vault. Which feature should be enabled?

A.Row-Level Security
B.Dynamic Data Masking
C.Always Encrypted with secure enclaves
D.Transparent Data Encryption (TDE) with customer-managed keys in Azure Key Vault
AnswerD

Transparent Data Encryption (TDE) encrypts the database at rest by performing real-time I/O encryption and decryption of data and log files, using a database encryption key (DEK) that is stored in the database boot record. When customer-managed keys are used, the DEK is protected by an asymmetric key stored in Azure Key Vault, enabling the customer to control and rotate the key hierarchy. This approach directly satisfies the requirement for encrypting on-premises databases at rest with customer-managed keys in Azure Key Vault, making it the correct option.

Why this answer

Transparent Data Encryption (TDE) with customer-managed keys in Azure Key Vault is the correct choice because it encrypts the entire database at rest using a symmetric key, and the option to use customer-managed keys (CMK) in Azure Key Vault satisfies the security team's requirement for full control over encryption keys. TDE performs real-time I/O encryption and decryption of data and log files, and when combined with Azure Key Vault, it supports bring-your-own-key (BYOK) scenarios, ensuring compliance with regulatory mandates for customer-managed key storage.

Exam trap

The trap here is that candidates may confuse Always Encrypted (which encrypts specific columns and requires client-side key management) with TDE (which encrypts the entire database at rest), leading them to choose option C because they think 'customer-managed keys' implies column-level encryption, but the requirement is for all data at rest, which TDE with Azure Key Vault fulfills.

How to eliminate wrong answers

Option A is wrong because Row-Level Security (RLS) controls access to rows in a table based on user identity or context, but it does not encrypt data at rest or involve key management. Option B is wrong because Dynamic Data Masking (DDM) obfuscates sensitive data in query results to unauthorized users, but it does not encrypt the underlying data at rest and does not use customer-managed keys. Option C is wrong because Always Encrypted with secure enclaves protects sensitive data in use and in transit by encrypting columns with client-side keys, but it does not encrypt the entire database at rest and does not natively integrate with Azure Key Vault for TDE-level customer-managed key storage; it focuses on column-level encryption and computations within enclaves, not full database encryption.

22
MCQmedium

Your organization uses Azure Storage for sensitive customer data. You need to ensure that data at rest is encrypted using a customer-managed key (CMK) stored in Azure Key Vault. Additionally, you want to automatically rotate the key every 90 days. What should you configure?

A.Enable Azure Disk Encryption on the storage account and store the key in Key Vault with rotation policy.
B.Enable server-side encryption with a platform-managed key and use Azure Policy to enforce rotation.
C.Use client-side encryption with .NET client library and implement custom rotation logic.
D.Enable Azure Storage encryption with a customer-managed key and configure a key rotation policy in Azure Key Vault.
AnswerD

Azure Storage encryption with a customer-managed key (CMK) allows you to specify a key stored in Azure Key Vault, which is used for server-side encryption of all data in the storage account. By configuring a key rotation policy in Key Vault, you can automatically rotate the key version at the desired interval, and the storage service will seamlessly use the new version without any manual intervention. This meets the requirement of both using a customer-managed key and enabling automated rotation through an Azure-native policy.

Why this answer

Azure Storage encryption with a customer-managed key (CMK) allows you to use your own key stored in Azure Key Vault to encrypt data at rest. By configuring a key rotation policy in Azure Key Vault, you can automatically rotate the key every 90 days, meeting both the CMK and rotation requirements without custom code.

Exam trap

The trap here is confusing Azure Disk Encryption (for VMs) with Azure Storage encryption (for data services), leading candidates to select Option A even though it does not apply to storage accounts.

How to eliminate wrong answers

Option A is wrong because Azure Disk Encryption is used for encrypting virtual machine disks, not Azure Storage account data; it does not apply to Blob, File, Queue, or Table storage. Option B is wrong because server-side encryption with a platform-managed key uses Microsoft-managed keys, not customer-managed keys, and Azure Policy cannot enforce key rotation for platform-managed keys. Option C is wrong because client-side encryption requires custom code to manage encryption and rotation logic, which is unnecessary when Azure Storage natively supports CMK with automatic rotation via Key Vault.

23
MCQmedium

You have an Azure Storage account that contains sensitive documents. You need to generate a time-limited, secure URL that allows a specific user to download a file without requiring storage account keys. What should you use?

A.Azure Front Door custom domain
B.Storage account access key
C.Shared Access Signature (SAS)
D.Azure RBAC role assignment
AnswerC

A Shared Access Signature (SAS) is URI-based delegated authorization that grants time-limited, permission-scoped access to a specific blob, container, or service. You can set an expiration time, allowed permissions (read, write, delete, etc.), and even IP restrictions if needed. This makes it the ideal way to share sensitive data securely without exposing account keys. SAS tokens are the only option here that directly produce a URL with embedded authorization for direct access.

Why this answer

A Shared Access Signature (SAS) is the correct choice because it provides delegated, time-limited access to a specific storage resource (e.g., a blob) without exposing the storage account keys. You can scope the SAS to a specific user by using a stored access policy or by generating a service SAS with fine-grained permissions, and you can enforce expiration and allowed IP ranges. This meets the requirement of a secure, time-bound URL for a single file download.

Exam trap

The trap here is that candidates often confuse RBAC (which controls access via Azure AD roles) with SAS (which generates a time-limited URL), leading them to choose RBAC because it seems more secure, but RBAC does not produce a direct download link and requires the user to have an Azure AD identity and appropriate permissions at the time of access.

How to eliminate wrong answers

Option A is wrong because Azure Front Door custom domain is a global load balancer and application delivery service; it does not generate time-limited, user-specific URLs for storage blobs. Option B is wrong because the storage account access key provides full administrative access to the entire storage account and cannot be scoped to a single file or user, nor can it be time-limited without regenerating the key. Option D is wrong because Azure RBAC role assignment controls management-plane and data-plane access via Azure AD, but it does not produce a URL; it requires the user to authenticate with Azure AD and does not provide a direct, time-limited download link.

24
MCQeasy

You need to ensure that Azure SQL Database connections are encrypted and the server's identity is verified. Which connection string parameter should be required?

A.Encrypt=Optional
B.Encrypt=True; TrustServerCertificate=False
C.TrustServerCertificate=True
D.Encrypt=False
AnswerB

This is the correct configuration for Azure SQL Database. Encrypt=True forces the client to use TLS for all data sent over the network, while TrustServerCertificate=False requires the client to validate the server's TLS certificate against a trusted root CA. Azure SQL Database's certificate chains are issued from trusted public CAs, so validation succeeds and the connection is both encrypted and protected against man-in-the-middle attacks.

Why this answer

Setting `Encrypt=True` forces TLS encryption for all data in transit between the client and Azure SQL Database, while `TrustServerCertificate=False` ensures that the server's TLS certificate is validated against a trusted certificate authority (CA). This combination provides both encryption and server identity verification, which is required for secure connections to Azure SQL Database.

Exam trap

The trap here is that candidates often assume `TrustServerCertificate=True` is sufficient for security, not realizing that it disables server identity verification, which is a critical component of a secure TLS connection.

How to eliminate wrong answers

Option A is wrong because `Encrypt=Optional` allows the client to connect without encryption if the server does not enforce it, which does not guarantee encryption. Option C is wrong because `TrustServerCertificate=True` bypasses certificate chain validation, meaning the server's identity is not verified, even if encryption is enabled. Option D is wrong because `Encrypt=False` disables encryption entirely, leaving the connection vulnerable to eavesdropping and man-in-the-middle attacks.

25
MCQmedium

Your organization uses Azure Storage accounts with blob containers. You need to ensure that only authorized applications can access the storage account, without using shared keys or shared access signatures. What should you configure?

A.Use a stored access policy with a shared access signature
B.Configure a firewall on the storage account to allow only the application's IP address
C.Enable a private endpoint for the storage account
D.Use Azure AD authentication with managed identities
AnswerD

Azure AD authentication with managed identities assigns an automatically managed service principal to the compute resource, and the SDK obtains an OAuth 2.0 token from Azure Instance Metadata Service without storing any secrets. The identity is then mapped to Azure RBAC roles such as Storage Blob Data Contributor/Reader, providing granular, revocable access. This eliminates shared-key management and clearly ties each request to an application identity, aligning with the requirement to authenticate without managing credentials.

Why this answer

Azure AD authentication with managed identities allows applications to authenticate to Azure Storage without using shared keys or SAS tokens. Managed identities provide an automatically managed identity in Azure AD, enabling applications to use OAuth 2.0 tokens for secure access to storage accounts. This approach eliminates the need for any shared secrets or keys, meeting the requirement exactly.

Exam trap

The trap here is that candidates often confuse network-level controls (firewall or private endpoint) with authentication mechanisms, mistakenly believing that restricting network access alone satisfies the requirement to avoid shared keys or SAS.

How to eliminate wrong answers

Option A is wrong because a stored access policy with a shared access signature still uses a SAS token, which is a shared key-based mechanism and does not eliminate the use of shared keys. Option B is wrong because configuring a firewall on the storage account to allow only the application's IP address does not authenticate the application; it only restricts network access and still requires shared keys or SAS for authorization. Option C is wrong because enabling a private endpoint ensures private network connectivity but does not replace the need for authentication; the application still requires shared keys, SAS, or Azure AD credentials to access the storage account.

26
Multi-Selectmedium

You are designing a backup strategy for Azure virtual machines. You need to ensure that backups are encrypted at rest and can be restored in a different Azure region in case of a regional disaster. Which two configurations should you use?

Select 2 answers
A.Configure Azure Site Recovery for the VMs
B.Enable encryption at rest for the Recovery Services vault using platform-managed keys
C.Enable Cross-Region Restore (CRR) for the Recovery Services vault
D.Enable Azure Disk Encryption on the VMs
E.Use geo-redundant storage (GRS) for the Recovery Services vault
AnswersB, C

Azure Backup automatically encrypts all backup data at rest in the Recovery Services vault using Storage Service Encryption (SSE), which by default is enforced with platform-managed keys. Enabling or confirming this default protects vaulted recovery points from storage-layer threats and unauthorized physical access without requiring you to manage key lifecycle. This is a foundational security control in any backup strategy, though it does not by itself address availability or regional resilience, which is handled separately by features like Cross-Region Restore.

Why this answer

Enabling encryption at rest for the Recovery Services vault using platform-managed keys ensures that backup data is encrypted when stored in Azure's storage layer. This is a default encryption mechanism that protects data at rest without requiring additional key management overhead. Option C is correct because Cross-Region Restore (CRR) allows you to restore backup data to a paired Azure region, providing disaster recovery capability if the primary region fails.

Exam trap

The trap here is that candidates often confuse Azure Site Recovery (disaster recovery) with backup services, or assume that enabling GRS alone allows cross-region restores, when in fact CRR is a separate configuration that must be explicitly enabled.

27
MCQhard

You have an Azure SQL Database that stores financial data. You need to prevent unauthorized access by encrypting specific columns containing credit card numbers. The solution must allow authorized applications to query the data transparently. What should you implement?

A.Azure Storage service encryption
B.Transparent Data Encryption (TDE)
C.Dynamic Data Masking
D.Always Encrypted
AnswerD

Always Encrypted is a client-side encryption technology that encrypts sensitive data in specific columns before it is ever sent to Azure SQL Database. The database engine only receives and stores ciphertext, and encryption/decryption occurs transparently inside the client application using a column encryption key protected by a column master key stored in Azure Key Vault or a Windows certificate store. This ensures that even database administrators and cloud operators cannot view the plaintext financial data. Authorized applications that hold the column master key can query and decrypt the data transparently, making Always Encrypted the correct choice for protecting individual financial columns.

Why this answer

Always Encrypted is the correct choice because it encrypts specific columns (e.g., credit card numbers) at the client-side, ensuring that the data remains encrypted both at rest and in transit, and only authorized applications with the column encryption key can decrypt and query the data transparently. This meets the requirement of preventing unauthorized access (including database administrators) while allowing transparent querying for authorized applications.

Exam trap

The trap here is that candidates often confuse Transparent Data Encryption (TDE) with column-level encryption, mistakenly believing TDE protects specific columns from unauthorized access, when in fact TDE only protects data at rest and does not prevent authorized database users or DBAs from reading the data.

How to eliminate wrong answers

Option A is wrong because Azure Storage service encryption encrypts data at rest for Azure Blob Storage, Files, and Queues, not for Azure SQL Database columns. Option B is wrong because Transparent Data Encryption (TDE) encrypts the entire database at rest (pages on disk) but does not protect data from unauthorized access during query execution or from database administrators who have access to the database. Option C is wrong because Dynamic Data Masking obfuscates data in query results for unauthorized users but does not encrypt the underlying data; it can be bypassed by users with elevated permissions or by querying the data directly.

28
MCQmedium

A company uses Azure Blob Storage to store sensitive documents. The security policy requires that the storage account can only be accessed from a specific Azure virtual network (VNet) and that all access must use Azure Active Directory (Azure AD) authentication. They want to block any access that uses storage account keys or shared access signatures (SAS). Which configuration should they implement?

A.Configure the storage account firewall to allow access from the specific VNet, and disable 'Allow storage account key access'.
B.Configure a private endpoint for the storage account and disable 'Allow storage account key access'.
C.Configure the storage account firewall to deny all networks, and set 'Allow storage account key access' to 'Disabled'.
D.Configure the storage account firewall to allow access from the specific VNet, and enable 'Require secure transfer' (HTTPS only).
AnswerA

Configuring the firewall with an allow rule for the specific VNet permits only traffic originating from that VNet's service endpoint or private endpoint, while setting 'Allow storage account key access' to Disabled forces Azure AD authentication by rejecting shared keys and SAS tokens. With this combination, clients in the allowed VNet must authenticate via Azure AD and be granted an RBAC role such as Storage Blob Data Reader or Storage Blob Data Contributor. This satisfies both the network restriction and the authentication requirement precisely.

Why this answer

It combines two essential controls: the storage account firewall restricts access to only the specified VNet, and disabling 'Allow storage account key access' enforces Azure AD authentication by blocking all requests that use account keys or SAS tokens. This ensures that only authenticated Azure AD identities from the allowed VNet can access the storage account, meeting the security policy requirements.

Exam trap

The trap here is that candidates often confuse 'Require secure transfer' (which only mandates HTTPS) with authentication enforcement, or assume that a private endpoint alone blocks key-based access, when in fact it only secures network connectivity.

How to eliminate wrong answers

Option B is wrong because while a private endpoint restricts network access to a specific VNet, disabling 'Allow storage account key access' alone does not block SAS tokens—SAS can still be generated and used unless explicitly disabled via other settings. Option C is wrong because denying all networks in the firewall blocks all traffic, including from the specific VNet, making the storage account inaccessible even with Azure AD authentication. Option D is wrong because enabling 'Require secure transfer' enforces HTTPS but does not block storage account keys or SAS tokens; it only ensures encrypted transport, not authentication method enforcement.

29
Drag & Dropmedium

Drag and drop the steps to configure Azure Defender for SQL on an Azure SQL Database into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Defender for SQL is enabled per database under security settings, requiring storage for scans.

30
Multi-Selecthard

You are configuring security for an Azure Functions app that processes credit card numbers. You need to ensure that the function can securely access a storage account without storing any credentials in code or configuration, and that all data in the storage account is encrypted with a customer-managed key. Which three actions should you take?

Select 3 answers
A.Assign the 'Storage Blob Data Contributor' role to the function app's managed identity
B.Configure the storage account to use customer-managed keys for encryption
C.Store the storage account connection string in an application setting
D.Enable system-assigned managed identity on the function app
E.Use a Key Vault reference in the function app configuration to retrieve the storage account key
AnswersA, B, D

Assigning the 'Storage Blob Data Contributor' role to the function app's managed identity grants data-plane access to the storage account through Azure AD RBAC rather than a shared key. This role gives the identity read/write/delete permissions on blob containers, and Azure AD-based access supports conditional access policies and operation logs for auditing. Since the identity is a security principal, the access can be revoked or scoped independently, eliminating the need to rotate credentials or store keys in configuration.

Why this answer

Assigning the 'Storage Blob Data Contributor' role to the function app's managed identity authorizes the function to read and write blobs in the storage account using Azure RBAC, without requiring any credentials in code or configuration. This aligns with the requirement to avoid storing credentials, as the managed identity provides a secure identity for the function app to authenticate to Azure services.

Exam trap

The trap here is that candidates often confuse using Key Vault references (which still rely on a stored secret) with managed identity authentication (which eliminates secrets entirely), leading them to select option E instead of the correct combination of managed identity and RBAC.

31
MCQmedium

Your organization uses Azure Storage for sensitive financial data. You need to restrict access to storage accounts based on the client's IP address. Which Azure Storage service feature should you configure?

A.Firewalls and virtual networks
B.Shared access signatures (SAS)
C.Azure Private Link
D.Azure AD role-based access control
AnswerA

Firewalls and virtual networks is the correct answer because it is the Azure Storage account networking feature that lets you define IP address rules, including ranges and specific IPs, to restrict access to the storage account. When you configure these firewall rules, only requests originating from allowed IP addresses (or from selected virtual networks using service endpoints) can reach the storage endpoint, effectively blocking all other clients. This directly satisfies the requirement to restrict storage access by IP address.

Why this answer

Firewalls and virtual networks allow you to restrict access to Azure Storage accounts based on source IP address ranges, including specific client IPs. This is the correct feature because it provides network-level access control that can block or allow traffic from defined IP addresses, which directly meets the requirement to restrict access based on the client's IP address.

Exam trap

The trap here is that candidates often confuse Shared Access Signatures (SAS) with network-level access control, mistakenly thinking SAS tokens can restrict by IP, when in fact SAS tokens only grant access to anyone holding the token unless you explicitly configure an IP ACL within the SAS token itself—but the question asks for a storage service feature, not a token-level option, and the correct answer is the Firewall and virtual networks feature.

How to eliminate wrong answers

Option B is wrong because Shared Access Signatures (SAS) provide time-limited, delegated access to specific storage resources via a token, but they do not restrict access based on the client's IP address; they grant access to anyone who possesses the token, regardless of their IP. Option C is wrong because Azure Private Link exposes the storage account over a private endpoint within a virtual network, which restricts access to traffic from that VNet but does not filter by client IP address; it is designed for private connectivity, not IP-based restrictions. Option D is wrong because Azure AD role-based access control (RBAC) manages authorization at the control plane (management operations) and data plane (via Azure AD authentication) but does not enforce network-level IP restrictions; it controls who can access the storage account, not from which IP addresses.

32
MCQmedium

A company stores sensitive job processing messages in Azure Queue Storage. They have a web application running on an Azure virtual machine in a VNet that reads and writes to the queue. The security team requires that only the web application's VM can access the queue, and all access from the public internet must be blocked. Which configuration should they implement?

A.Configure a service endpoint for Azure Storage on the VNet subnet and add a firewall rule allowing the VNet.
B.Deploy a private endpoint for the storage account in the same VNet and disable public network access on the storage account.
C.Route all traffic from the VNet through an Azure Firewall and create a NAT rule to the storage account.
D.Generate a shared access signature (SAS) token with narrow permissions and require the web app to use that token.
AnswerB

This is correct because a private endpoint assigns the storage account a private IP address from the VNet's address space, and all traffic to the storage account is routed over the Microsoft backbone rather than the public internet. Disabling public network access on the storage account then blocks every connection that does not originate from that private endpoint. Together these controls enforce a network-level isolation boundary, ensuring that only resources inside the VNet can reach the queue messages and no external client or public internet path exists.

Why this answer

Deploying a private endpoint for the storage account in the same VNet assigns the storage account a private IP from the VNet, effectively bringing the service into the VNet. Disabling public network access then ensures that all traffic to the queue must traverse the private endpoint, blocking any public internet access. This meets the requirement that only the web application's VM can access the queue, as the private endpoint is accessible only from within that VNet.

Exam trap

The trap here is that candidates often confuse service endpoints (which only extend VNet identity but leave the public endpoint exposed) with private endpoints (which fully remove public exposure), leading them to choose option A instead of B.

How to eliminate wrong answers

Option A is wrong because a service endpoint for Azure Storage on the VNet subnet only extends the VNet identity to the storage account but does not remove the public endpoint; the storage account remains accessible from the public internet unless additional firewall rules explicitly block all other traffic, which is not specified. Option C is wrong because routing traffic through an Azure Firewall with a NAT rule does not inherently block public internet access to the storage account; the storage account's public endpoint would still be reachable from the internet, and the NAT rule only translates traffic, not restrict source. Option D is wrong because a shared access signature (SAS) token with narrow permissions does not restrict network-level access; the storage account's public endpoint remains accessible from the internet, and any client with the SAS token (including potentially malicious actors) could access the queue from anywhere.

33
Drag & Dropmedium

Drag and drop the steps to implement Azure AD Identity Protection to detect risky sign-ins into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Identity Protection policies are configured under Security, with user risk policy settings.

34
MCQmedium

You are a security engineer for a company that uses Azure SQL Database. The database contains sensitive financial data and is currently encrypted with Transparent Data Encryption (TDE) using a service-managed key. A new policy requires that the TDE protector be a customer-managed key stored in Azure Key Vault, and that the key be automatically rotated every 90 days. You have created an Azure Key Vault and generated a key. What should you do next to meet the policy?

A.Create a new Azure SQL Database with the customer-managed key as the TDE protector, and migrate the data.
B.Configure the SQL server's TDE protector to use the customer-managed key from Key Vault, and enable auto-rotation on the key.
C.Enable Always Encrypted on the database and use the customer-managed key for column encryption.
D.Store the customer-managed key in Azure Key Vault and configure the database to use it for backup encryption.
AnswerB

To use a customer-managed key for TDE, you must configure the Azure SQL logical server to use the key from Key Vault as the TDE protector. Azure Key Vault supports automatic key rotation, which can be set to rotate every 90 days. This satisfies both the requirement for customer-managed key and automatic rotation. The SQL server must have a managed identity with appropriate permissions to access the key vault.

Why this answer

To meet the policy, you must set the Azure SQL logical server's TDE protector to the customer-managed key stored in Azure Key Vault. Azure Key Vault supports automatic key rotation, which can be configured for 90-day rotation. This ensures the database is encrypted with a customer-managed key and the key is rotated regularly.

Other options either address different features (Always Encrypted) or involve unnecessary migration.

Exam trap

The trap here is thinking that Always Encrypted or backup encryption settings are needed for TDE with customer-managed keys.

35
MCQmedium

A company is enabling Azure Disk Encryption (ADE) on Windows virtual machines. They have enabled soft-delete on Azure Key Vault and configured a Key Encryption Key (KEK). However, the disk encryption fails with an error indicating that the key vault does not have the required permissions. What is the most likely missing configuration?

A.The Key Vault access policy does not grant the Azure Disk Encryption service principal the 'unwrap key' and 'wrap key' permissions.
B.The Key Vault firewall is blocking the Azure platform.
C.The VM does not have a managed identity assigned.
D.The KEK is in a different Azure region than the VM.
AnswerA

Correct. Azure Disk Encryption (ADE) relies on the Azure Disk Encryption service principal (AzureDiskEncryption) to access your Key Vault. When a KEK is used, that service principal must be granted the 'unwrap key' and 'wrap key' permissions in the Key Vault's access policy; otherwise, the service cannot decrypt or re-encrypt the disk encryption key. The error you see is a classic permissions failure, not a network or identity issue, because the service principal lacks the required cryptographic operations on the vault's keys.

Why this answer

Azure Disk Encryption (ADE) requires the Azure Disk Encryption service principal (also known as the Azure Disk Encryption service) to have 'unwrap key' and 'wrap key' permissions on the Key Vault. These permissions allow the service to encrypt and decrypt the disk encryption keys using the Key Encryption Key (KEK). Without these specific cryptographic permissions, the encryption operation fails, even if soft-delete and a KEK are correctly configured.

Exam trap

The trap here is that candidates often confuse the required permissions for ADE with general Key Vault access policies (e.g., 'get' and 'list') or mistakenly think a managed identity or firewall configuration is the root cause, rather than recognizing the need for explicit 'wrap key' and 'unwrap key' permissions for the Azure Disk Encryption service principal.

How to eliminate wrong answers

Option B is wrong because the Key Vault firewall, if enabled, would block external access, but the error message specifically indicates a permissions issue, not a network connectivity problem. Option C is wrong because a managed identity is not required for ADE on Windows VMs; ADE uses the Azure Disk Encryption service principal, not the VM's identity, to access the Key Vault. Option D is wrong because the KEK can be in a different region than the VM; ADE supports cross-region key references as long as the Key Vault is in the same Azure subscription and the service principal has the required permissions.

36
MCQmedium

A company stores sensitive healthcare data in Azure SQL Database. They need to encrypt specific columns containing patient diagnosis codes so that even database administrators with the 'sysadmin' role cannot view the plaintext. The application must be able to perform equality searches (WHERE clauses) on the encrypted columns. Which encryption technology should they implement?

A.Transparent Data Encryption (TDE)
B.Always Encrypted (deterministic encryption)
C.Row-Level Security (RLS)
D.Dynamic Data Masking (DDM)
AnswerB

Always Encrypted is the correct choice because it encrypts selected column data between the client application and the database engine, with the column encryption keys never being passed to or stored in SQL Database in plaintext. The client-side driver performs encryption and decryption, so the database engine only ever sees ciphertext; even a sysadmin with full server access cannot view the sensitive values without the client-held Column Master Key. Deterministic encryption is specifically suitable here because it allows equality comparison and inner join operations on the ciphertext, enabling indexed equality searches on fields like national identifiers or medical record numbers while still shielding the values from DBAs.

Why this answer

Always Encrypted with deterministic encryption ensures that sensitive columns are encrypted at the client side, so the encryption keys are never revealed to the database engine, including sysadmin roles. Deterministic encryption generates the same ciphertext for the same plaintext, enabling equality searches (WHERE clauses) on encrypted columns without exposing plaintext data to the server.

Exam trap

The trap here is that candidates confuse encryption at rest (TDE) with client-side column-level encryption, failing to recognize that TDE does not protect data from privileged users who can run queries, while Always Encrypted does by keeping keys off the server.

How to eliminate wrong answers

Option A is wrong because Transparent Data Encryption (TDE) encrypts the entire database at rest (pages on disk) but does not protect data from database administrators who have access to the decrypted data in memory or via queries. Option C is wrong because Row-Level Security (RLS) controls access to rows based on user predicates but does not encrypt data; it relies on database permissions and can be bypassed by privileged users. Option D is wrong because Dynamic Data Masking (DDM) obfuscates data in query results for non-privileged users but does not encrypt the underlying data; privileged users like sysadmin can still view plaintext by querying directly.

37
MCQmedium

A company uses Azure SQL Database for a critical application. Security policy requires that all client connections to the database use at least TLS 1.2 encryption. What configuration change must be made to enforce this requirement?

A.Configure the minimum TLS version in the SQL server's settings.
B.Enable Transparent Data Encryption (TDE).
C.Update the server firewall rules to allow only specific IP addresses.
D.Implement Always Encrypted for all sensitive columns.
AnswerA

Configuring the minimum TLS version at the Azure SQL logical server level directly enforces the encryption-protocol policy for all incoming client connections. When set to 1.2, the server rejects any TLS handshake attempt using 1.0 or 1.1, ensuring only modern, secure transport is used. This is the specific control that guarantees data is encrypted in transit between clients and the database.

Why this answer

To enforce that all client connections to Azure SQL Database use at least TLS 1.2, you must configure the minimum TLS version at the SQL server level. This setting overrides the default behavior, which allows older, less secure TLS versions, and ensures that any connection attempt using TLS 1.0 or 1.1 is rejected. The configuration is made in the Azure portal under the SQL server's 'Connectivity' settings or via the 'Minimal TLS Version' property in ARM templates or PowerShell.

Exam trap

The trap here is that candidates often confuse encryption at rest (TDE) or column-level encryption (Always Encrypted) with encryption in transit, leading them to select options that do not enforce the TLS protocol version.

How to eliminate wrong answers

Option B is wrong because Transparent Data Encryption (TDE) encrypts data at rest, not data in transit, so it does not enforce TLS version requirements. Option C is wrong because firewall rules control network access by IP address, not the encryption protocol or TLS version used for the connection. Option D is wrong because Always Encrypted protects sensitive columns with client-side encryption, but it does not enforce a minimum TLS version for the overall connection; it can even work over TLS 1.0 if the server allows it.

38
MCQmedium

You have an Azure SQL Database that contains sensitive customer data. You need to ensure that database administrators (DBAs) cannot view the data in the 'CreditCard' column. What should you implement?

A.Enable Transparent Data Encryption (TDE) on the database.
B.Use Always Encrypted with column encryption key stored in Azure Key Vault.
C.Implement Azure SQL Auditing for the database.
D.Configure Dynamic Data Masking for the 'CreditCard' column.
AnswerB

Always Encrypted is a client-side encryption technology where sensitive column data is encrypted in the application layer before it is ever sent to SQL Database. The column encryption key is stored in Azure Key Vault and never exposed to the database engine, so SQL Server sees only ciphertext and returns only ciphertext to the client. Even if a DBA has full server permissions, they cannot decrypt the data without the column encryption key, making it the only option here that truly prevents DBAs from viewing plaintext CreditCard data.

Why this answer

Always Encrypted ensures that sensitive data, such as the 'CreditCard' column, is encrypted at rest and in transit, and that the encryption keys are never exposed to the database engine. By storing the column encryption key in Azure Key Vault, DBAs with full server access cannot decrypt the data because they lack access to the key material. This provides client-side encryption where only authorized applications with the key can view plaintext data.

Exam trap

The trap here is that candidates often confuse Dynamic Data Masking (which can be bypassed by privileged users) with Always Encrypted (which provides cryptographic separation of duties), leading them to choose masking as a simpler solution without realizing it does not protect against DBAs.

How to eliminate wrong answers

Option A is wrong because Transparent Data Encryption (TDE) encrypts the entire database at rest but does not prevent DBAs from viewing data while the database is online; TDE protects against offline theft of physical files, not against authorized database administrators. Option C is wrong because Azure SQL Auditing logs database events but does not restrict or encrypt data access; it only provides an audit trail of who viewed data, not a control to prevent viewing. Option D is wrong because Dynamic Data Masking obfuscates the 'CreditCard' column in query results for non-privileged users, but DBAs with elevated permissions (e.g., db_owner) can bypass the mask by using direct queries or altering the masking rule.

39
MCQmedium

A company stores sensitive data in Azure Blob Storage. They use customer-managed keys (CMK) stored in Azure Key Vault for encryption at rest. The security policy requires that the encryption keys be automatically rotated every 90 days. Which configuration should they implement to meet this requirement without manual intervention?

A.Enable key auto-rotation in Key Vault by setting a rotation policy on the key.
B.Use a custom Azure Automation runbook to rotate the key.
C.Set a key expiration date of 90 days and manually renew.
D.Enable versioning on the storage account and manually create a new key version.
AnswerA

Key Vault's rotation policy is the native mechanism that automatically generates new key versions at a defined interval (e.g., 90 days) or before an expiry date, without any custom code or manual action. For storage encryption, a versionless key URI in the storage account automatically references the latest rotated version, minimizing disruption. This directly satisfies the requirement for automatic rotation.

Why this answer

Azure Key Vault supports automatic key rotation by configuring a rotation policy on the key. When you enable auto-rotation, Key Vault automatically creates a new key version at the specified interval (e.g., every 90 days) without any manual intervention. This directly satisfies the requirement for automatic rotation of customer-managed keys used for Azure Storage encryption at rest.

Exam trap

The trap here is that candidates may think custom automation (Option B) is required for key rotation, but Azure Key Vault's built-in auto-rotation feature directly meets the requirement without additional overhead.

How to eliminate wrong answers

Option B is wrong because using a custom Azure Automation runbook introduces unnecessary complexity and potential failure points; Key Vault natively supports automatic rotation, making a custom solution redundant. Option C is wrong because setting a key expiration date only marks the key as expired after 90 days but does not automatically rotate it; manual renewal is required, which violates the 'without manual intervention' requirement. Option D is wrong because enabling versioning on the storage account only allows storing multiple blob versions, not key rotation; manually creating a new key version in Key Vault still requires manual action and does not automate the rotation process.

40
MCQeasy

A company deploys a public-facing web application behind Azure Application Gateway. They want to enable the Web Application Firewall (WAF) to protect against SQL injection and cross-site scripting attacks. During the initial testing phase, they want to identify malicious requests without blocking them, to tune the WAF rules before enabling full protection. Which WAF mode should they configure?

A.Prevention mode
B.Detection mode
C.Logging mode
D.Off
AnswerB

Detection mode configures the WAF policy to pass every request through to the backend while evaluating it against the enabled rule sets, and any matches are recorded in the WAF log for later analysis. Because no request is denied, legitimate traffic cannot be interrupted, making it the appropriate setting for identifying attacks and tuning rules before enabling enforcement. This is the exact behavior needed by the team during the validation phase.

Why this answer

Detection mode logs WAF alerts and records the full request details without blocking any traffic. This allows the security team to analyze malicious requests, tune rule exclusions, and validate that legitimate traffic is not falsely flagged before switching to Prevention mode. It is the correct choice for the initial testing phase described.

Exam trap

The trap here is that candidates may confuse Detection mode with a hypothetical 'Logging mode' or assume Prevention mode is needed for any protection, overlooking the explicit requirement to identify without blocking during tuning.

How to eliminate wrong answers

Option A is wrong because Prevention mode actively blocks malicious requests, which would disrupt testing and prevent the team from tuning rules based on observed traffic. Option C is wrong because Azure WAF does not have a 'Logging mode'; logging is a feature enabled within Detection or Prevention mode, not a standalone operational mode. Option D is wrong because Off disables the WAF entirely, providing no protection or logging of malicious requests, which defeats the purpose of the testing phase.

41
MCQmedium

A healthcare organization stores sensitive patient data in Azure SQL Database. They need to encrypt specific columns containing medical history so that even database administrators with highly privileged roles, such as 'sysadmin', cannot view the plaintext data. Additionally, they need to support complex queries on the encrypted data, including pattern matching and range comparisons. Which encryption technology should they implement?

A.Always Encrypted with secure enclaves
B.Transparent Data Encryption (TDE)
C.Dynamic Data Masking
D.Row-Level Security
AnswerA

Always Encrypted with secure enclaves performs client-side column encryption, so the database engine only ever processes ciphertext while the encryption keys are held outside SQL Server. The enclave—a trusted hardware environment such as Intel SGX inside Azure Confidential Computing—enables rich operations like pattern matching, range comparisons, and sorting without ever exposing plaintext to the database process. This makes it the only option that both prevents database administrators from seeing data and supports computed queries over encrypted columns.

Why this answer

Always Encrypted with secure enclaves is correct because it encrypts specific columns at the client side, ensuring that even database administrators with sysadmin privileges cannot view the plaintext data. The secure enclave feature allows computations (such as pattern matching and range comparisons) to be performed on the encrypted data inside a trusted execution environment, which is required by the question's need for complex queries on encrypted columns.

Exam trap

The trap here is that candidates often confuse Transparent Data Encryption (TDE) with column-level encryption, assuming TDE protects data from privileged users, but TDE only protects data at rest and does not prevent authorized database users from reading plaintext data.

How to eliminate wrong answers

Option B (Transparent Data Encryption) is wrong because it encrypts the entire database at rest (on disk) but does not protect data from users or administrators who have access to the database engine; the data is decrypted transparently when queried, so sysadmins can still view plaintext. Option C (Dynamic Data Masking) is wrong because it only obfuscates data in query results for unauthorized users, but the underlying data remains stored in plaintext and can be accessed by privileged users like sysadmins. Option D (Row-Level Security) is wrong because it controls access to rows based on user context but does not encrypt the data; privileged users can still read the plaintext data directly.

42
MCQhard

An Azure Storage account is configured with server-side encryption (SSE) using a customer-managed key stored in Azure Key Vault. The security team requires that the storage account's identity be used to authenticate to the key vault for key access. Additionally, they want the identity to be automatically deleted when the storage account is deleted. Which type of identity should they assign to the storage account?

A.System-assigned managed identity
B.User-assigned managed identity
C.Service principal
D.Azure AD user account
AnswerA

A system-assigned managed identity is created directly on the storage account and shares its lifecycle: when enabled, Azure AD automatically provisions a corresponding service principal for the account, and when the storage account is deleted, the identity is removed automatically. It requires no application ID, client secret, or certificate rotation, so it meets both requirements of credential-free authentication and automatic cleanup. The storage account can use this identity to authenticate to Azure Key Vault for customer-managed key operations.

Why this answer

A system-assigned managed identity is tied to the lifecycle of the Azure resource (the storage account) and is automatically deleted when the resource is deleted. This identity can be used to authenticate to Azure Key Vault for accessing the customer-managed key used in server-side encryption (SSE), satisfying the security team's requirement for automatic deletion upon storage account deletion.

Exam trap

The trap here is that candidates often confuse user-assigned managed identities with system-assigned ones, overlooking the critical lifecycle coupling requirement that system-assigned identities are automatically deleted with the parent resource, while user-assigned identities persist independently.

How to eliminate wrong answers

Option B is wrong because a user-assigned managed identity has an independent lifecycle and is not automatically deleted when the storage account is deleted; it must be manually removed. Option C is wrong because a service principal is a separate application identity that requires manual credential management (secrets or certificates) and does not automatically delete with the storage account. Option D is wrong because an Azure AD user account is a human identity that cannot be assigned to an Azure resource and would require interactive authentication, which is not suitable for automated key access.

43
MCQmedium

A company uses Azure Managed Disks for their virtual machines. They want to ensure that all managed disks are encrypted at rest using a customer-managed key (CMK) stored in Azure Key Vault. They also want to automatically revoke access to the disks if the key is disabled or deleted. Which feature should they configure?

A.Azure Disk Encryption (ADE) with a Key Encryption Key (KEK)
B.Server-side encryption with customer-managed keys (SSE-CMK)
C.Azure Storage Service Encryption (SSE) with platform-managed keys
D.Azure Key Vault soft-delete and purge protection
AnswerB

Server-side encryption with customer-managed keys (SSE-CMK) is the native Azure managed-disk encryption feature that encrypts disk data at rest using a customer-provided key from Azure Key Vault or a managed HSM. Because the managed-disk service must unwrap the disk encryption key from the CMK for every attach and I/O operation, disabling or deleting the CMK makes the disk inaccessible and fully satisfies the key-revocation requirement without any in-VM agent or manual configuration. This approach works at the platform layer, applying encryption to all writes sent to the disk, and is the preferred way to achieve both encryption at rest and customer-controlled revocation.

Why this answer

Server-side encryption with customer-managed keys (SSE-CMK) encrypts Azure Managed Disks at rest using a key stored in Azure Key Vault. When the key is disabled or deleted, Azure automatically revokes access to the disk by failing any I/O operations that require that key, ensuring the disk becomes inaccessible. This directly meets the requirement for both CMK-based encryption and automatic access revocation upon key loss.

Exam trap

The trap here is that candidates confuse Azure Disk Encryption (ADE) with server-side encryption (SSE-CMK), mistakenly thinking ADE provides automatic access revocation when the key is disabled, whereas ADE only encrypts at the guest OS level and does not enforce platform-level access control based on key state.

How to eliminate wrong answers

Option A is wrong because Azure Disk Encryption (ADE) with a KEK uses BitLocker (Windows) or DM-Crypt (Linux) to encrypt the OS and data disks at the VM guest OS level, not at the Azure platform level, and disabling the KEK does not automatically revoke access to the underlying managed disk; the disk remains accessible at the storage layer. Option C is wrong because Azure Storage Service Encryption (SSE) with platform-managed keys uses Microsoft-managed keys, not customer-managed keys, so it cannot meet the requirement for CMK-based encryption or allow key revocation by the customer. Option D is wrong because Azure Key Vault soft-delete and purge protection only prevents permanent deletion of keys and secrets; it does not encrypt disks or automatically revoke access to disks when a key is disabled or deleted.

44
MCQmedium

Your company uses Azure SQL Managed Instance. You need to ensure that all connections from clients use TLS 1.2 or higher. What should you configure?

A.Set the 'Minimal TLS version' property to 1.2 in the Managed Instance settings
B.Configure a firewall rule to block non-TLS 1.2 connections
C.Create an Azure Policy to require TLS 1.2 for all SQL Managed Instances
D.Enable the 'Force encryption' option on the client side
AnswerA

The Minimal TLS version property on Azure SQL Managed Instance is the native server-side setting that enforces the lowest TLS protocol accepted for client connections. Setting it to 1.2 rejects any handshake attempt using TLS 1.0 or 1.1 before the session is established, independent of the client driver or connection string. This is the only direct control that guarantees all connections use at least TLS 1.2.

Why this answer

Azure SQL Managed Instance exposes a 'Minimal TLS version' property in its settings that enforces the minimum TLS version for all client connections. Setting this to 1.2 ensures that any connection attempt using TLS 1.0 or 1.1 is rejected at the server level, providing a centralized, server-side enforcement mechanism without relying on client-side configurations.

Exam trap

The trap here is that candidates often confuse 'Force encryption' (which only ensures encryption, not a specific TLS version) with the 'Minimal TLS version' setting, or mistakenly think Azure Policy or firewall rules can directly control TLS protocol negotiation at the connection level.

How to eliminate wrong answers

Option B is wrong because firewall rules in Azure SQL Managed Instance control IP-based access, not TLS protocol versions; they cannot inspect or block connections based on the TLS version used. Option C is wrong because Azure Policy can audit or enforce compliance at the resource level (e.g., requiring the 'Minimal TLS version' property to be set to 1.2), but it does not directly enforce TLS version on connections—it only ensures the setting is configured correctly. Option D is wrong because enabling 'Force encryption' on the client side only mandates that the connection be encrypted (using TLS), but it does not specify or enforce a minimum TLS version; clients could still connect using TLS 1.0 or 1.1.

45
MCQeasy

You are the Azure Security Engineer for a company that uses Azure SQL Database. A recent security audit requires that all connections to the database be encrypted and that the database reject any unencrypted connections. You need to enforce this requirement with the least administrative effort. What should you do?

A.Configure a firewall rule on the Azure SQL Database server to allow only connections from specific IP addresses.
B.Implement Always Encrypted on all sensitive columns in the database.
C.Enable Transparent Data Encryption (TDE) on the Azure SQL Database.
D.Enable the 'Enforce SSL connection' setting on the Azure SQL Database server.
AnswerD

Azure SQL Database provides a server-level setting called 'Enforce SSL connection' (or 'Require secure transfer' in some interfaces). When enabled, the server rejects any connection that is not encrypted with TLS. This is a simple configuration change that enforces encryption for all connections to the database, meeting the audit requirement with minimal effort.

Why this answer

The 'Enforce SSL connection' setting on the Azure SQL Database server forces all connections to use TLS encryption. When enabled, any attempt to connect without encryption is rejected. This directly satisfies the requirement to encrypt all connections and reject unencrypted ones, and it requires only a single configuration change.

Exam trap

The trap here is confusing data-at-rest encryption features like TDE or Always Encrypted with transport encryption enforcement.

46
Drag & Dropmedium

Drag and drop the steps to enable Azure Security Center's enhanced security features for a subscription into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

To enable Azure Security Center's enhanced security features for a subscription, you must first navigate to Security Center, then access 'Security policy' under Management. Within that blade, select the target subscription and set its pricing tier to Standard. This activates advanced threat detection and vulnerability assessment capabilities.

Common mistakes include confusing the order of subscription selection and tier setting, or mixing up the security policy with auto-provisioning settings.

47
Multi-Selecthard

Which THREE capabilities are provided by Azure Storage Service Encryption (SSE) when using customer-managed keys?

Select 3 answers
A.Auditing of key usage via Azure Key Vault logs.
B.Client-side encryption of data before upload.
C.Automatic encryption of data at rest.
D.Ability to rotate keys periodically.
E.Control access to the storage account using RBAC.
AnswersA, C, D

Auditing of key usage via Azure Key Vault logs: When Azure Storage accesses a customer-managed key stored in Key Vault to encrypt or decrypt data at rest, the Key Vault records the operation, such as key wrap or unwrap, in its diagnostic logs. By enabling Key Vault auditing, you can monitor key usage, detect unauthorized access, and meet compliance requirements. This capability is present specifically when SSE is configured with customer-managed keys, not with Microsoft-managed keys.

Why this answer

Azure Storage Service Encryption (SSE) with customer-managed keys integrates with Azure Key Vault, which can be configured to log key operations such as encrypt, decrypt, wrap, and unwrap. These logs are sent to Azure Monitor or a storage account, enabling auditing of key usage for compliance and security monitoring.

Exam trap

The trap here is that candidates confuse SSE's server-side encryption with client-side encryption (Option B) or mix up access control mechanisms (RBAC) with encryption capabilities, leading them to select options that are valid Azure features but not provided by SSE.

48
MCQmedium

Your company uses Azure SQL Database to store customer data. You need to ensure that database administrators cannot access sensitive columns (e.g., credit card numbers) even during maintenance. What should you implement?

A.Transparent Data Encryption
B.Dynamic Data Masking
C.Row-level security
D.Always Encrypted
AnswerD

Always Encrypted protects sensitive columns by encrypting data in the client-side driver before it is transmitted to SQL Server, so the database engine only receives and stores ciphertext. The cryptographic keys are held outside the server—in the application’s keystore or Azure Key Vault—and are never provided to the database engine. As a result, not even a DBA with sysadmin privileges can decrypt or view the plaintext values when querying the column, since the server lacks the key material. This is the only option among these that enforces client-side encryption to defeat elevated database permissions.

Why this answer

Always Encrypted ensures that sensitive columns like credit card numbers are encrypted at all times — both at rest and in transit — and that the encryption keys are never revealed to the database engine. This means database administrators (DBAs) cannot decrypt the data even during maintenance, because the decryption happens only on the client side. This directly meets the requirement to prevent DBA access to sensitive columns.

Exam trap

The trap here is that candidates often confuse Dynamic Data Masking with Always Encrypted, thinking masking prevents DBA access, but masking is easily bypassed by privileged users, whereas Always Encrypted provides cryptographic separation of duties.

How to eliminate wrong answers

Option A is wrong because Transparent Data Encryption (TDE) encrypts the entire database at rest but does not protect data from DBAs who have access to the database engine and can query the data while it is in use. Option B is wrong because Dynamic Data Masking only obfuscates data in query results for non-privileged users, but DBAs with elevated permissions can bypass the mask and see the actual values. Option C is wrong because Row-level security controls access to rows based on predicates but does not encrypt or hide column values from DBAs who can query the table.

49
MCQhard

A company stores sensitive files in Azure Files shares. They require encryption at rest using customer-managed keys (CMK) and encryption in transit using SMB 3.0 encryption. They have created a premium Azure Files share in a storage account and configured encryption at rest with a CMK. However, clients are able to connect without enforcing SMB encryption. What additional configuration is necessary to ensure that all connections to the file share are encrypted in transit?

A.Enable the 'Secure transfer required' property on the storage account.
B.Configure a network security group (NSG) to allow only encrypted traffic.
C.Set the minimum SMB protocol version to 3.0 on the file share.
D.Create a service endpoint for the storage account.
AnswerA

Enabling the storage account's 'Secure transfer required' property rejects requests over unencrypted connections. For Azure Files, this forces clients to use SMB 3.0 with encryption (or HTTPS for REST), so sensitive data is encrypted while traversing the network. This is the proper, supported control for enforcing encryption in transit for Azure Files.

Why this answer

Enabling the 'Secure transfer required' property on the storage account enforces encryption in transit for all client connections, including SMB 3.0 encryption for Azure Files. Without this setting, clients can connect using unencrypted SMB 2.1 or SMB 3.0 without encryption, even if the file share itself supports encryption. This property is a storage account-level flag that rejects any request not using HTTPS or SMB 3.0 with encryption.

Exam trap

The trap here is that candidates confuse protocol version enforcement (Option C) with encryption enforcement, not realizing that SMB 3.0 can be used without encryption unless the 'Secure transfer required' property is explicitly enabled.

How to eliminate wrong answers

Option B is wrong because a network security group (NSG) filters traffic at the network layer based on IP addresses and ports, but cannot inspect or enforce SMB encryption at the application layer; it would only block or allow traffic on port 445, not differentiate between encrypted and unencrypted SMB connections. Option C is wrong because setting the minimum SMB protocol version to 3.0 on the file share only restricts the protocol version, but SMB 3.0 can operate without encryption (encryption is an optional feature within SMB 3.0); this does not enforce encryption in transit. Option D is wrong because creating a service endpoint for the storage account secures traffic to the Azure backbone network but does not enforce encryption in transit; it only ensures traffic stays within the Azure network, leaving the connection potentially unencrypted.

50
Multi-Selecteasy

A company stores sensitive financial records in Azure Blob Storage. They want to ensure that if a blob is deleted or overwritten, it can be recovered within 30 days. They also want to protect against accidental deletion of the storage account itself. Which two configurations should they implement? (Choose two.)

Select 2 answers
A.Enable blob soft delete with a retention period of 30 days
B.Enable storage account soft delete with a retention period of 30 days
C.Enable container soft delete with a retention period of 30 days
D.Enable blob versioning
AnswersA, B

Blob soft delete retains deleted or overwritten blobs for a configurable retention period (here, 30 days), so a mistakenly deleted financial record can be undeleted from the soft-deleted state. Unlike versioning, it explicitly covers deletion events, and unlike container soft delete, it operates at the individual blob level, which is where the company's sensitive files live. This makes it a direct data-recovery safeguard for the scenario.

Why this answer

Blob soft delete (Option A) protects individual blobs by retaining deleted or overwritten blobs for a specified retention period, allowing recovery within that window. Storage account soft delete (Option B) protects the entire storage account from accidental deletion by retaining the deleted account for a configurable period. Together, they address both the blob-level and account-level recovery requirements for the 30-day window.

Exam trap

The trap here is that candidates often confuse blob versioning with soft delete, assuming versioning alone provides deletion recovery, but versioning only protects against overwrites, not deletions, and lacks a configurable retention period for recovery.

51
MCQmedium

A company has an Azure SQL Database that stores personally identifiable information (PII) in columns. They need to encrypt those columns so that only authorized applications can decrypt the data, and even database administrators cannot view the plaintext. Additionally, they need to support equality comparisons (WHERE clauses) on the encrypted columns. Which encryption technology should they use?

A.Always Encrypted with deterministic encryption
B.Always Encrypted with randomized encryption
C.Transparent Data Encryption (TDE)
D.Dynamic Data Masking
AnswerA

Always Encrypted with deterministic encryption encrypts PII client-side so the SQL engine and database administrators never see plaintext. It uses a deterministic algorithm where the same plaintext always produces the same ciphertext for a given column encryption key, enabling the server to perform equality comparisons in WHERE, JOIN, and GROUP BY clauses. This supports business queries that require filtering on PII (e.g., searching by social security number) while preserving confidentiality. However, deterministic encryption can reveal equality patterns and is less secure than randomized, but it remains the correct choice for applications needing strict DBA access control.

Why this answer

Always Encrypted with deterministic encryption is the correct choice because it encrypts PII columns at the client side, ensuring that even database administrators cannot view plaintext data. Deterministic encryption generates the same ciphertext for the same plaintext, which allows equality comparisons (WHERE clauses) on encrypted columns, meeting the requirement for query support.

Exam trap

The trap here is that candidates often confuse Always Encrypted with TDE, thinking TDE provides client-side encryption and column-level query support, but TDE only encrypts data at rest and does not prevent database administrators from seeing plaintext data in memory or during queries.

How to eliminate wrong answers

Option B is wrong because Always Encrypted with randomized encryption does not support equality comparisons; it produces different ciphertext for the same plaintext, making WHERE clauses impossible on encrypted columns. Option C is wrong because Transparent Data Encryption (TDE) encrypts data at rest (the entire database file) but does not protect data from database administrators who have access to the database engine, and it does not support column-level encryption or client-side key control. Option D is wrong because Dynamic Data Masking only obfuscates data at query results for unauthorized users, but the underlying data remains in plaintext in storage and can be accessed by administrators or through direct queries.

52
MCQmedium

You manage Azure Storage accounts for a healthcare organization. To comply with HIPAA, you need to ensure that all data at rest is encrypted and that encryption keys are rotated automatically every 90 days. What should you implement?

A.Configure Azure RBAC roles for storage accounts.
B.Enable infrastructure encryption for storage accounts.
C.Generate new storage account access keys manually every 90 days.
D.Use customer-managed keys (CMK) in Azure Key Vault with automatic key rotation.
AnswerD

Customer-managed keys in Azure Key Vault let you supply the key encryption key (KEK) that wraps the data encryption key (DEK) used to encrypt every storage object, giving you full control over key lifecycle. When you enable automatic key rotation, Azure Key Vault creates a new key version according to the rotation policy you define, and Azure Storage re-wraps the DEK without any downtime or data re-encryption. This directly satisfies both the encryption-at-rest and automatic-rotation requirements, which is why it is the correct choice.

Why this answer

Customer-managed keys (CMK) stored in Azure Key Vault with automatic key rotation fulfill the requirement for encrypted data at rest and automatic rotation of encryption keys. This ensures that HIPAA compliance is met by maintaining control over encryption keys and enforcing their periodic rotation. The other options do not provide automatic key rotation: RBAC controls access but does not rotate keys; infrastructure encryption adds another layer but does not include key rotation; manually rotating storage account access keys addresses authentication keys, not encryption keys, and is not automatic.

Exam trap

The main trap is confusing storage account access keys (used for authentication) with encryption keys (used for data at rest). Candidates may choose manual rotation of access keys, but that does not meet the automatic rotation requirement for encryption keys and only addresses a different type of key.

How to eliminate wrong answers

Option A is wrong because Azure RBAC roles control access permissions to storage accounts (e.g., who can read/write data), not encryption or key rotation. Option B is wrong because infrastructure encryption adds an extra layer of encryption at the infrastructure level but does not manage or rotate access keys. Option C is wrong because manually generating new storage account access keys every 90 days is error-prone, does not scale, and does not meet the requirement for automatic rotation; it also does not address encryption at rest with customer-controlled keys.

53
MCQhard

You are deploying an Azure SQL Database with a security alert policy as shown in the exhibit. Which statement is true?

A.Alerts are enabled and notifications are sent to both account admins and admin@contoso.com.
B.Email notifications are sent only to admin@contoso.com.
C.Alerts are not retained because retentionDays is set to 30.
D.All alerts are disabled because disabledAlerts is empty.
AnswerA

This configuration is correct because the security alert policy has its state set to Enabled, meaning alerts are actively generated. With emailAccountAdmins set to true, all Azure subscription account administrators receive alert notifications, and since emailAddresses explicitly includes admin@contoso.com, that address is also notified. Thus alerts go to both account admins and the specified email address.

Why this answer

The security alert policy in Azure SQL Database has 'state' set to 'Enabled' and 'emailAddresses' includes both 'admin@contoso.com' and the account admins (via 'emailAccountAdmins' set to true). This means alerts are active and notifications are sent to both the specified email and the account administrators, making option A correct.

Exam trap

The trap here is that candidates often assume an empty 'disabledAlerts' list means all alerts are disabled, but in Azure SQL Database, an empty list means no alerts are excluded, so all are enabled by default.

How to eliminate wrong answers

Option B is wrong because the policy explicitly sets 'emailAccountAdmins' to true, so notifications are sent to account admins in addition to admin@contoso.com, not only to admin@contoso.com. Option C is wrong because 'retentionDays' set to 30 controls how long alert data is retained in the log, not whether alerts are enabled or disabled; alerts are still generated and sent. Option D is wrong because an empty 'disabledAlerts' array means no specific alert types are disabled, so all alerts are enabled by default, not disabled.

54
Multi-Selecthard

Which two security configurations should you apply to an Azure SQL Database to meet a requirement for data protection at rest and in transit?

Select 2 answers
A.Enable Microsoft Defender for Azure SQL.
B.Use Always Encrypted for sensitive columns.
C.Enable Transparent Data Encryption (TDE).
D.Configure firewall rules to allow only trusted IP addresses.
E.Enable Azure SQL Auditing.
AnswersB, C

Use Always Encrypted for sensitive columns: Correct. It encrypts sensitive data both at rest and in transit by keeping encryption keys on the client side.

Why this answer

Option B (Always Encrypted for sensitive columns) is correct because Always Encrypted protects sensitive data both at rest and in transit by keeping data encrypted on the client side, so the database engine never sees plaintext — the column encryption keys are never exposed to Azure SQL Database. Option C (Transparent Data Encryption, TDE) is correct because TDE performs real-time encryption and decryption of the database, backups, and transaction log files at rest using a symmetric database encryption key protected by a certificate stored in Azure Key Vault or the service-managed key store, satisfying the data-at-rest requirement. Option A (Microsoft Defender for Azure SQL) is not correct here because it is a threat detection and vulnerability assessment service, not a data encryption mechanism for protecting data at rest or in transit.

Option D (firewall rules to allow only trusted IP addresses) is not correct because it is network access control, not encryption of data at rest or in transit. Option E (Azure SQL Auditing) is not correct because auditing tracks and logs database events for compliance and forensic purposes, but it does not encrypt or protect the data itself.

Exam trap

The trap here is that candidates often confuse Transparent Data Encryption (TDE) with protecting data in transit, but TDE only encrypts data at rest (the database files and backups), not data moving between the client and server.

55
MCQhard

A company uses Azure SQL Database with Transparent Data Encryption (TDE) and a customer-managed key (CMK) stored in Azure Key Vault. The Key Vault has a firewall that blocks all public access. The SQL server is a managed service that needs to access the key to perform TDE operations. The Key Vault is in the same Azure region as the SQL server. Which additional configuration is needed?

A.Enable 'Allow trusted Microsoft services to bypass this firewall' in the Key Vault firewall settings
B.Configure a service endpoint for Microsoft.KeyVault on the SQL server's subnet
C.Assign the SQL server's server identity the 'Contributor' role on the Key Vault
D.Create a private endpoint for the Key Vault in the SQL server's virtual network
AnswerA

The Key Vault firewall blocks all data plane access by default, which would break TDE key operations. Enabling 'Allow trusted Microsoft services to bypass this firewall' explicitly authorizes Azure SQL Database (as a trusted Microsoft service) to reach the vault for wrap/unwrap operations, provided the SQL server's managed identity is also granted the correct RBAC role or access policy. This is the standard configuration when using customer-managed keys for TDE on Azure SQL Database while the vault firewall is turned on.

Why this answer

When Azure Key Vault has a firewall that blocks all public access, Azure services like SQL Database that need to access the key for TDE operations must be explicitly allowed. Enabling 'Allow trusted Microsoft services to bypass this firewall' permits the SQL server's managed service identity to authenticate and retrieve the CMK from Key Vault, even when public network access is denied. This setting is required because the SQL server, as a platform-as-a-service (PaaS) resource, does not reside in a virtual network by default and cannot use a private endpoint or service endpoint without additional networking configuration.

Exam trap

The trap here is that candidates often assume a private endpoint or service endpoint is always required for secure access, but for PaaS services like Azure SQL Database that use managed identities, the 'Allow trusted Microsoft services' setting is the simplest and correct solution when the Key Vault firewall blocks public access.

How to eliminate wrong answers

Option B is wrong because configuring a service endpoint for Microsoft.KeyVault on the SQL server's subnet is not applicable—Azure SQL Database is a PaaS service that does not have a subnet in a virtual network by default; service endpoints are used for VNet-integrated resources like VMs or App Service, not for SQL Database's managed identity access to Key Vault. Option C is wrong because assigning the 'Contributor' role on the Key Vault grants excessive permissions (e.g., ability to modify keys) and is not required; the SQL server's identity only needs the 'Get' and 'Unwrap Key' permissions on the key itself, which are granted via a Key Vault access policy, not RBAC roles. Option D is wrong because creating a private endpoint for Key Vault in the SQL server's virtual network would require the SQL server to be integrated into a VNet, which is not the default configuration for Azure SQL Database; private endpoints are used for network isolation but do not solve the firewall bypass issue for a managed service that needs to reach Key Vault over the public endpoint.

56
MCQeasy

You run the PowerShell cmdlet shown in the exhibit for an Azure SQL Database. What is the security implication?

A.Auditing of database queries is not configured.
B.The database is not protected against anomalous activities.
C.The database firewall allows all public IP addresses.
D.Transparent data encryption is not enabled.
AnswerB

The PowerShell cmdlet output indicates that Advanced Threat Protection is disabled on the Azure SQL Database. With ATP disabled, the service does not analyze database activity for anomalies such as SQL injection attempts, unusual access patterns, or brute-force attacks, leaving the database without this specific protective layer. This is the direct and accurate interpretation of the cmdlet result, as ATP is exactly the feature that protects against anomalous activities.

Why this answer

The cmdlet shown is `Set-AzSqlDatabaseVulnerabilityAssessmentSettings`, which enables Vulnerability Assessment (VA) but does not enable Advanced Threat Protection (ATP). Without ATP, the database lacks anomaly detection capabilities such as SQL injection detection, brute-force attack alerts, and unusual access pattern monitoring. Therefore, the database is not protected against anomalous activities, making option B correct.

Exam trap

The trap here is that candidates confuse Vulnerability Assessment (which scans for misconfigurations and missing patches) with Advanced Threat Protection (which detects ongoing anomalous activities), leading them to overlook the specific security gap of missing anomaly detection.

How to eliminate wrong answers

Option A is wrong because auditing is configured separately via `Set-AzSqlDatabaseAuditing` or the Azure portal; the cmdlet shown does not affect auditing settings. Option C is wrong because firewall rules are managed via `Set-AzSqlServerFirewallRule` or the portal, and the cmdlet does not modify IP allow lists. Option D is wrong because Transparent Data Encryption (TDE) is enabled by default for new Azure SQL Databases and is managed via `Set-AzSqlDatabaseTransparentDataEncryption`; the cmdlet shown does not disable TDE.

57
MCQhard

You are deploying a critical application on Azure Virtual Machines that must remain highly available. You need to implement a security solution that ensures the application can recover from a ransomware attack that encrypts all data disks. What is the most cost-effective approach?

A.Configure Azure Backup with immutable vault and soft delete.
B.Use Azure Files share with snapshots for the application data.
C.Enable Azure Site Recovery for the virtual machines.
D.Take daily snapshots of the disks and store them in the same storage account.
AnswerA

Azure Backup's immutable vault (now generally available as immutable vault for Azure Backup) enforces a Write-Once, Read-Many (WORM) policy on recovery points, preventing ransomware from encrypting or deleting backups even with compromised administrator credentials. Soft delete adds a configurable retention window during which deleted backup data is retained and recoverable, giving defenders a second chance to restore from an attack. This layered approach directly addresses the backup integrity and recoverability requirements for a critical application, making it the correct choice.

Why this answer

Azure Backup with an immutable vault and soft delete (option A) is the most cost-effective solution because it provides ransomware-resistant, tamper-proof recovery points for the VM data disks at a lower cost than full VM replication, and immutability plus soft delete prevents attackers from deleting or altering backups during an attack. Azure Site Recovery (option C) is designed for disaster recovery and VM replication, which is more expensive and not specifically aimed at protecting backup data from ransomware. Azure Files snapshots (option B) only apply to Azure Files shares, not VM data disks, so they cannot protect the application's disk data.

Daily disk snapshots stored in the same storage account (option D) are not immutable and can be deleted or encrypted along with the source data, making them a weak ransomware defense.

58
MCQmedium

A company stores sensitive customer data in an Azure Storage account. The security policy requires that all data be encrypted at rest using a customer-managed key (CMK) stored in Azure Key Vault. They also need the ability to disable the key in case of a security breach and have the data become inaccessible immediately. Which feature should they enable on the storage account to achieve this?

A.Enable Azure Storage encryption with customer-managed keys (CMK)
B.Use service-managed keys (SSE) with platform-managed keys
C.Enable Azure Disk Encryption on VMs that access the storage account
D.Configure Azure Information Protection for the storage account
AnswerA

Azure Storage always encrypts data at rest with AES-256, but enabling customer-managed keys (CMK) lets you supply your own key in Azure Key Vault or Managed HSM. You control the key lifecycle, rotation, and revocation; if you disable or delete the key, Azure Storage begins rejecting blob operation requests and the data becomes inaccessible. There is a short delay of up to 24 hours before the cached key is evicted, which is why revocation is not instantaneous. This meets the requirement of giving the customer the ability to revoke access on demand, which is the core control needed here.

Why this answer

Enabling Azure Storage encryption with customer-managed keys (CMK) allows the customer to use their own key stored in Azure Key Vault for encrypting the storage account data at rest. The key can be disabled or revoked in Key Vault, which immediately renders the data inaccessible because Azure Storage uses the key to wrap the data encryption key; without access to the CMK, decryption cannot occur.

Exam trap

The trap here is that candidates often confuse Azure Disk Encryption (which encrypts VM disks) with storage account encryption, or assume that platform-managed keys (SSE) provide the same revocation capability as customer-managed keys.

How to eliminate wrong answers

Option B is wrong because service-managed keys (SSE) with platform-managed keys do not allow the customer to control or disable the key; Microsoft manages the keys, so the customer cannot revoke access in a breach scenario. Option C is wrong because Azure Disk Encryption encrypts the OS and data disks of VMs, not the data stored in Azure Storage accounts; it does not provide encryption at rest for the storage account itself. Option D is wrong because Azure Information Protection is a classification and labeling service for documents and emails, not a storage encryption mechanism; it does not encrypt data at rest in Azure Storage accounts.

59
MCQhard

Your company uses Azure SQL Database and wants to protect sensitive data stored in a column named 'CreditCardNumber'. You need to ensure that the data is encrypted at rest and that only authorized users can decrypt the data at the application layer. Additionally, you want to prevent unauthorized administrators from accessing the plaintext. Which solution should you implement?

A.Enable Transparent Data Encryption (TDE) and store the encryption key in Azure Key Vault
B.Use Dynamic Data Masking to mask the credit card column for non-privileged users
C.Implement Azure SQL Database's Always Encrypted with enclaves
D.Implement Always Encrypted and store the column encryption key in Azure Key Vault
AnswerD

Always Encrypted is a client-side encryption technology that encrypts sensitive column data before it is sent to Azure SQL Database, so the database engine and its administrators never see plaintext. The application's driver uses the column encryption key (CEK) to encrypt and decrypt, while the CEK is wrapped by a column master key (CMK); storing the CMK in Azure Key Vault provides centralized, audited key management without exposing the CEK to the database server. Because only client applications possessing the necessary key material can decrypt the credit card values, database administrators and cloud operators are prevented from viewing the data.

Why this answer

Always Encrypted ensures that sensitive data, such as credit card numbers, is encrypted at rest and remains encrypted throughout its lifecycle, including during query processing. By storing the column encryption key in Azure Key Vault, you separate key management from the database, preventing even database administrators from accessing plaintext data. Only authorized applications with access to the key can decrypt the data at the application layer, meeting all stated requirements.

Exam trap

The trap here is confusing Transparent Data Encryption (TDE) with Always Encrypted; TDE protects at rest but not from database administrators or during query processing, whereas Always Encrypted provides client-side encryption that prevents even the database engine from seeing plaintext data.

How to eliminate wrong answers

Option A is wrong because Transparent Data Encryption (TDE) encrypts the entire database at rest but does not protect data from database administrators or during query execution; it also does not enforce application-layer decryption. Option B is wrong because Dynamic Data Masking only obfuscates data in query results for non-privileged users but does not encrypt data at rest or prevent privileged users from accessing plaintext. Option C is wrong because Always Encrypted with enclaves allows computations on encrypted data within a secure enclave, which is unnecessary here and introduces additional complexity; the core requirement of application-layer decryption with key separation is met by standard Always Encrypted.

60
MCQeasy

You need to securely connect to an Azure SQL Database from an on-premises application without exposing the database to the public internet. Which solution should you use?

A.Configure a firewall rule to allow the on-premises public IP address
B.Use Azure Private Link to connect via a private endpoint
C.Enable Always Encrypted on the database
D.Use a virtual network service endpoint for Azure SQL Database
AnswerB

Azure Private Link creates a private endpoint inside your virtual network, assigning the database a private IP address that is reachable only through your network. On-premises clients can securely connect to this endpoint via a VPN gateway or ExpressRoute, ensuring traffic never traverses the public internet. This eliminates exposure to the public endpoint and provides the highest level of network security for connecting to Azure SQL Database.

Why this answer

Azure Private Link allows you to access Azure SQL Database over a private endpoint within your virtual network, using a private IP address from your on-premises network via ExpressRoute or VPN. This ensures traffic never traverses the public internet, meeting the requirement for secure, non-public connectivity.

Exam trap

The trap here is that candidates often confuse service endpoints (which still use the public endpoint) with private endpoints (which provide truly private connectivity), leading them to choose Option D thinking it eliminates internet exposure.

How to eliminate wrong answers

Option A is wrong because configuring a firewall rule to allow the on-premises public IP address still exposes the database to the public internet, as traffic flows over the internet and the database endpoint remains publicly resolvable. Option C is wrong because Always Encrypted is a client-side encryption feature that protects data at rest and in transit, but it does not control network connectivity or prevent public internet exposure. Option D is wrong because a virtual network service endpoint for Azure SQL Database still uses the database's public endpoint, and traffic from on-premises would need to traverse the internet unless routed through a VPN/ExpressRoute, which still leaves the endpoint publicly accessible.

61
MCQhard

You are designing a secure data solution for a financial application. The data must be encrypted at rest, in transit, and in use. You choose Azure SQL Database. Which combination of features should you implement?

A.Transparent Data Encryption, enforce TLS, and Always Encrypted
B.Azure Information Protection, Dynamic Data Masking, and column-level security
C.Always Encrypted, Azure Active Directory authentication, and Azure Information Protection
D.Transparent Data Encryption, Dynamic Data Masking, and Azure Active Directory authentication
AnswerA

Transparent Data Encryption (TDE) encrypts database files, backups, and transaction logs at rest, ensuring stored data is unreadable without the database encryption key. Enforcing TLS 1.2+ protects data in transit between the application and Azure SQL, preventing man-in-the-middle interception. Always Encrypted encrypts sensitive columns client-side so the SQL engine never sees plaintext values, covering the data-in-use state during query processing. Together they comprehensively protect data at rest, in transit, and in use.

Why this answer

It addresses all three encryption states required by the scenario: Transparent Data Encryption (TDE) encrypts data at rest, enforcing TLS secures data in transit, and Always Encrypted protects data in use by keeping encryption keys client-side, ensuring plaintext data never appears in the database engine.

Exam trap

The trap here is that candidates often confuse Dynamic Data Masking with encryption, but masking only hides data from unauthorized users at query time while the underlying data remains unencrypted, failing the 'encrypted in use' requirement.

How to eliminate wrong answers

Option B is wrong because Azure Information Protection is a classification and labeling service, not an encryption mechanism for data at rest or in use; Dynamic Data Masking only obfuscates data at query time but does not encrypt it; column-level security controls access but does not encrypt data. Option C is wrong because Azure Active Directory authentication provides identity management, not encryption for data at rest or in transit; Azure Information Protection again does not encrypt database data. Option D is wrong because Dynamic Data Masking does not encrypt data in use or in transit; Azure Active Directory authentication does not provide encryption for data in transit or in use.

62
MCQhard

You are the security engineer for a healthcare company that uses Azure to store electronic health records (EHR) in Azure Blob Storage. Compliance requires that all data be encrypted at rest with customer-managed keys stored in a hardware security module (HSM), that the storage account be accessible only from a specific virtual network, and that all access to the storage account be logged and sent to a central security information and event management (SIEM) system. Additionally, you must ensure that any blobs containing protected health information (PHI) are automatically labeled with a sensitivity label that prevents them from being shared externally. You have decided to use Azure Key Vault Managed HSM for key storage, Azure Private Endpoint for network access, and Azure Monitor for logging. However, you are unsure how to automatically apply sensitivity labels to blobs based on content inspection. Which service should you use to achieve automatic labeling of PHI data in Azure Blob Storage?

A.Microsoft Defender for Storage with sensitivity labeling integration
B.Azure Policy with custom policies to tag blobs containing PHI
C.Microsoft Purview Information Protection with auto-labeling policies for Azure Blob Storage
D.Microsoft Sentinel with analytics rules to detect PHI and apply labels via automation
AnswerC

Purview Information Protection auto-labelling policies scan blob content and apply sensitivity labels automatically, and those labels travel with the data to block external sharing. This satisfies the content-inspection requirement that Key Vault Managed HSM, Private Endpoint and Azure Monitor do not address.

Why this answer

Microsoft Purview Information Protection with auto-labeling policies for Azure Blob Storage (option C) is the correct choice because it is the service designed to scan and classify data in Azure Blob Storage using sensitive information types and then automatically apply sensitivity labels that enforce protection such as preventing external sharing. It integrates with the same Microsoft Purview compliance stack that provides sensitivity labels, so labels applied to blobs can carry encryption and sharing restrictions. The other options do not provide native automatic sensitivity labeling: Defender for Storage (A) offers threat detection and can integrate with Purview labeling but does not itself perform content-based auto-labeling, Azure Policy (B) can audit or tag resources but cannot inspect blob content or apply sensitivity labels, and Microsoft Sentinel (D) is a SIEM/SOAR tool for detection and automation, not a data classification and labeling engine.

63
MCQeasy

You need to protect Azure VMs from ransomware by ensuring that encrypted file systems cannot be read by attackers. Which solution should you implement?

A.Apply network security groups (NSGs) to block unauthorized access.
B.Configure Azure Backup for the VMs.
C.Enable Azure Disk Encryption on the VMs.
D.Enable Microsoft Defender for Cloud on the subscription.
AnswerC

Azure Disk Encryption (ADE) uses BitLocker on Windows and DM-Crypt on Linux to encrypt every OS and data disk at rest, so ransomware cannot read or recover plaintext data even if it gains storage-level access. ADE stores disk encryption keys in Azure Key Vault, optionally wrapped by a key encryption key (KEK), enabling dual encryption and stronger key governance. This directly ensures the VM disks are unreadable without proper key access, satisfying the core protection requirement.

Why this answer

Azure Disk Encryption uses BitLocker (Windows) or DM-Crypt (Linux) to encrypt the OS and data disks of Azure VMs at rest. This ensures that even if an attacker gains access to the underlying storage or exports the VHD files, the encrypted file system cannot be read without the encryption keys, which are protected by Azure Key Vault. This directly addresses the requirement to prevent attackers from reading encrypted file systems.

Exam trap

The trap here is that candidates often confuse network-level controls (NSGs) or backup solutions with data-at-rest encryption, or they assume that a security monitoring tool like Defender for Cloud provides encryption, when in fact only a dedicated disk encryption solution like Azure Disk Encryption protects the file system from being read by an attacker with access to the storage.

How to eliminate wrong answers

Option A is wrong because NSGs filter network traffic at the subnet or NIC level and do not protect data at rest on the VM's disks; they cannot prevent an attacker from reading the file system if they gain administrative access or access the underlying storage. Option B is wrong because Azure Backup creates recovery point copies of VM data but does not encrypt the live file system; it protects against data loss, not against unauthorized reading of the current encrypted file system. Option D is wrong because Microsoft Defender for Cloud provides threat detection, security posture management, and recommendations but does not itself encrypt disks; it may recommend enabling encryption but does not implement the encryption required to protect file systems from being read by attackers.

64
MCQmedium

You are the Azure Security Engineer for a healthcare company that stores patient imaging data in an Azure Storage account. The compliance team requires that all data written to the account be encrypted with a customer-managed key stored in Azure Key Vault, and that this key be automatically rotated every 12 months. You configure a customer-managed key for the storage account. Which additional configuration must you apply to meet the automatic rotation requirement?

A.Create an Azure Automation runbook that updates the storage account encryption key version every 12 months.
B.Enable Azure Defender for Storage and set the key rotation period in the Defender for Cloud security policy.
C.In Azure Key Vault, configure a key rotation policy on the customer-managed key that rotates the key every 12 months.
D.In the storage account's encryption settings, set the key rotation interval to 12 months and enable auto-rotation.
AnswerC

Azure Key Vault supports key rotation policies that automatically generate a new key version on a schedule. When the storage account references the key without a specific version, it will automatically use the latest version, so rotating the key in Key Vault every 12 months meets the requirement. This is the supported and recommended approach for automatic key rotation.

Why this answer

Customer-managed keys for Azure Storage encryption are stored in Azure Key Vault. To automatically rotate the key, you configure a rotation policy on the key itself in Key Vault. The storage account should reference the key without a specific version so that it always uses the latest key version.

This native integration ensures seamless rotation without manual intervention or custom scripting.

Exam trap

The trap here is assuming that Azure Storage provides a built-in key rotation interval setting, when rotation must actually be configured on the Key Vault key itself.

65
MCQhard

Your organization uses Azure Files shares for user home directories. You need to enforce that users access these shares only from trusted locations (corporate IP ranges) and that all access is logged. Which combination of actions should you take?

A.Use a Private Endpoint for the storage account and configure a service endpoint on the virtual network.
B.Generate a shared access signature (SAS) token that is valid only from corporate IPs and attach it to the file share.
C.Configure a storage account firewall to allow only the corporate IP range, and enable diagnostic settings to send logs to a Log Analytics workspace.
D.Assign Azure AD DS to the storage account and enable Azure AD authentication for Azure Files, then configure conditional access policies.
AnswerC

A storage account firewall is a network-level access control that evaluates the source IP of every request to the Azure Files endpoint, so locking it to the corporate IP range prevents all other clients from reaching the share over SMB or REST. Enabling diagnostic settings exports StorageRead and StorageWrite operation logs to a Log Analytics workspace, giving you a queryable record of access attempts, successful reads, and failures. Together, they enforce the IP restriction and provide the visibility needed to audit and alert on file share activity.

Why this answer

Azure Files supports network security via storage account firewalls, which can restrict access to specific IP ranges. Enabling diagnostic settings allows sending logs (e.g., to a Log Analytics workspace) for auditing. Option C correctly combines both requirements.

Option A is incorrect because Private Endpoints and service endpoints provide network isolation but do not filter by IP source. Option B is incorrect because while a SAS token can include an IP restriction, it is not designed for persistent user access to home directories and complicates management. Option D is incorrect because Azure AD DS and conditional access control authentication but do not enforce network-level IP restrictions.

66
MCQmedium

A company uses Azure SQL Database with Transparent Data Encryption (TDE) protected by a customer-managed key (CMK) stored in Azure Key Vault. The Key Vault has a firewall enabled that denies all public network access. The SQL server is a Microsoft service. How can the SQL server be granted access to the key vault to perform TDE operations?

A.Create a private endpoint on the Key Vault for the SQL server
B.Disable the Key Vault firewall
C.Enable the 'Allow trusted Microsoft services to bypass the firewall' setting on the Key Vault
D.Assign the SQL server a system-assigned managed identity and grant it access to the key vault
AnswerC

This setting permits Azure Key Vault to accept requests from Azure SQL Database and other first-party Microsoft services even when the firewall is enabled, without opening the vault to public internet traffic. The service's request originates from Azure's internal infrastructure, and the firewall bypass is combined with strict identity-based authorization via the SQL server's managed identity and access policies. It directly addresses the network-layer restriction for TDE operations while keeping the vault protected against all other external clients.

Why this answer

Azure Key Vault's firewall includes a setting to 'Allow trusted Microsoft services to bypass this firewall.' Azure SQL Database is a trusted Microsoft service, so enabling this setting allows the SQL server to authenticate to Key Vault using its system-assigned managed identity to retrieve the customer-managed key for TDE operations, without needing to disable the firewall or create a private endpoint.

Exam trap

The trap here is that candidates often think a private endpoint is required for PaaS services to access a firewalled Key Vault, but they overlook that Azure SQL Database is a trusted Microsoft service that can bypass the firewall with the appropriate setting, and that a private endpoint would require the SQL server to be network-integrated, which it is not by default.

How to eliminate wrong answers

Option A is wrong because creating a private endpoint on the Key Vault for the SQL server would require the SQL server to be in a virtual network, but Azure SQL Database is a platform-as-a-service (PaaS) resource that does not reside in a customer VNet by default; a private endpoint on Key Vault does not directly grant the SQL server network access. Option B is wrong because disabling the Key Vault firewall would expose the vault to all public network traffic, violating the security requirement to deny all public network access. Option D is wrong because while assigning a system-assigned managed identity and granting it access to the key vault is necessary for authentication and authorization, it does not solve the network connectivity issue caused by the Key Vault firewall blocking all public traffic; the managed identity alone cannot bypass the firewall without the 'Allow trusted Microsoft services' setting.

67
MCQeasy

You need to ensure that an Azure Key Vault is accessible only from a specific virtual network and that all operations are logged. What should you configure?

A.Key Vault firewall and virtual network service endpoints, and diagnostic settings
B.Azure RBAC roles and diagnostic settings
C.Soft-delete and purge protection, and diagnostic settings
D.Azure Policy and diagnostic settings
AnswerA

Enabling the Key Vault firewall with an "Allow selected networks" rule and configuring virtual network service endpoints for Microsoft.KeyVault restricts data-plane access to approved virtual networks and specified IP CIDRs. This is the enforcement mechanism that determines whether a request originates from an allowed network before the vault processes it. Adding diagnostic settings then captures audit and authentication logs, giving you the observability needed to verify that only permitted clients reached the vault.

Why this answer

To restrict Key Vault access to a specific virtual network, you must configure the Key Vault firewall and virtual network service endpoints, which allow you to deny all traffic except that originating from the specified VNet/subnet. To log all operations, you must configure diagnostic settings to send audit events (e.g., AuditEvent logs) to a Log Analytics workspace, Storage account, or Event Hub. Option A is correct because it combines both network access control and logging requirements.

Exam trap

The trap here is that candidates often confuse Azure RBAC (which controls permissions) with network-level access controls, or they think Azure Policy alone can enforce VNet restrictions, but Policy only audits or enforces configuration settings—it does not configure the actual firewall rules or diagnostic logging.

How to eliminate wrong answers

Option B is wrong because Azure RBAC roles control data-plane permissions (who can read/write secrets) but do not restrict network-level access to a specific virtual network; they cannot enforce the VNet-only connectivity requirement. Option C is wrong because soft-delete and purge protection are recovery and data retention features that prevent accidental or malicious deletion, not network access restrictions or logging. Option D is wrong because Azure Policy enforces compliance rules (e.g., requiring Key Vaults to have firewall enabled) but does not itself configure the VNet-specific firewall rules or enable diagnostic logging for the Key Vault.

68
MCQhard

You are deploying a three-tier application on Azure VMs. The web tier must be accessible from the internet, but the application and database tiers must only accept traffic from the web tier. You need to implement network segmentation using Azure networking components. What is the most secure and manageable solution?

A.Use a single subnet and configure NSGs on VM NICs to restrict traffic.
B.Use VNet peering to connect separate VNets for each tier and use NSGs.
C.Use a single VNet with one subnet and use Azure Firewall to filter traffic between tiers.
D.Use separate subnets for each tier in the same VNet and configure NSGs to allow traffic only from the previous tier.
AnswerD

Segmenting the VNet into separate subnets for each tier is the core of Azure network security for app workloads, because it lets you attach an NSG at the subnet boundary and enforce least-privilege traffic flow. For example, you can create a rule that allows only the application subnet to access the database subnet on TCP 1433, and only the web subnet to access the application subnet on TCP 443, while the default deny-all rule blocks everything else. Because NSGs are stateful, rules apply to both directions and new VMs added to a subnet automatically inherit the same security posture, providing a scalable, manageable tier-isolation pattern.

Why this answer

Placing each tier in its own subnet within the same VNet allows you to apply Network Security Groups (NSGs) at the subnet level with inbound rules that restrict traffic to only the previous tier's subnet IP range. This follows the principle of least privilege and provides a clear, manageable boundary between tiers without introducing unnecessary complexity or performance overhead.

Exam trap

The trap here is that candidates often overcomplicate the solution by choosing Azure Firewall or VNet peering, not realizing that NSGs on separate subnets within the same VNet are the simplest, most cost-effective, and most secure way to enforce east-west traffic restrictions between application tiers.

How to eliminate wrong answers

Option A is wrong because using a single subnet with NSGs on individual VM NICs does not provide network-level segmentation; it relies on host-level filtering, which is harder to manage at scale and does not prevent lateral movement between VMs in the same subnet. Option B is wrong because VNet peering between separate VNets introduces unnecessary latency, complexity, and cost; it is overkill for a simple three-tier application that can be contained within a single VNet. Option C is wrong because Azure Firewall is a stateful, centralized service designed for perimeter and hub-spoke scenarios, not for internal subnet-to-subnet filtering within a single VNet; using it here would add unnecessary cost and latency compared to NSG rules.

69
MCQhard

A company uses Azure SQL Database to store personally identifiable information (PII). They need to encrypt specific columns containing social security numbers so that even database administrators with the 'db_owner' role cannot view the plaintext. The application must be able to perform equality searches on the encrypted columns. Which encryption technology should they implement?

A.Transparent Data Encryption (TDE)
B.Always Encrypted with deterministic encryption
C.Dynamic Data Masking
D.Row-Level Security
AnswerB

Always Encrypted encrypts sensitive columns in the client driver using a column encryption key, which is protected by a column master key held outside SQL Server in Azure Key Vault or Windows Certificate Store. The SQL Server Database Engine receives only ciphertext and never sees the plaintext, so DBAs cannot read the data. With deterministic encryption, the same plaintext always produces the same ciphertext, allowing the server to perform equality comparisons (e.g., WHERE clause lookups) without exposing the values.

Why this answer

Always Encrypted with deterministic encryption is the correct choice because it encrypts specific columns at the client-side, ensuring that even database administrators with db_owner cannot view plaintext data. Deterministic encryption generates the same ciphertext for a given plaintext value, enabling equality searches (e.g., WHERE SSN = '123-45-6789') directly on the encrypted column without decrypting the data on the server.

Exam trap

The trap here is that candidates often confuse encryption at rest (TDE) with client-side column encryption, mistakenly believing TDE protects against privileged users, but TDE only protects against physical theft of the database files, not against authorized database access.

How to eliminate wrong answers

Option A is wrong because Transparent Data Encryption (TDE) encrypts the entire database at rest (pages written to disk) but does not protect data from users or DBAs who have access to the database; plaintext is visible to anyone with query permissions. Option C is wrong because Dynamic Data Masking obfuscates data in query results for non-privileged users but does not encrypt the underlying data; DBAs with db_owner can still view the unmasked values by altering the masking rule or querying directly. Option D is wrong because Row-Level Security restricts access to rows based on a predicate function but does not encrypt column values; DBAs with db_owner can bypass or modify the security policy to see all data.

70
MCQhard

A company uses Azure Key Vault to store secrets for their applications. They want to ensure that an application hosted on an Azure virtual machine can access secrets from only a specific Key Vault, and that all traffic between the VM and Key Vault remains within the Azure network and does not traverse the public internet. Which configuration should they implement?

A.Create a private endpoint for Key Vault in the same VNet as the VM and disable public network access on the Key Vault.
B.Enable the Key Vault firewall and add the VM's public IP address to the allowed list.
C.Use a service endpoint for Key Vault on the VM's subnet, and assign a managed identity to the VM.
D.Assign a system-assigned managed identity to the VM and grant it access to the Key Vault.
AnswerA

A private endpoint attaches a network interface with a private IP from your VNet directly to Key Vault, so all requests from the VM resolve to that IP and traverse the Azure backbone rather than the public internet. Disabling public network access on the vault, which means setting the firewall's default action to deny and allowing only private endpoint connections, ensures that no traffic can reach the vault through its public DNS name or IP. This combination gives the required private connectivity and eliminates any accidental public exposure, which is why it is the correct choice.

Why this answer

It combines a private endpoint for Azure Key Vault with disabling public network access. A private endpoint assigns a private IP address from the VM's VNet to the Key Vault, ensuring all traffic stays within the Microsoft Azure backbone network and never traverses the public internet. Disabling public network access on the Key Vault firewall then blocks any attempts to access the vault via its public endpoint, enforcing that only traffic through the private endpoint is allowed.

Exam trap

The trap here is that candidates often confuse service endpoints with private endpoints, not realizing that service endpoints still use the public endpoint of the resource and do not provide true private IP-based isolation, while private endpoints assign a private IP and can fully disable public access.

How to eliminate wrong answers

Option B is wrong because adding the VM's public IP address to the Key Vault firewall allows traffic that still traverses the public internet; it does not keep traffic within the Azure network. Option C is wrong because a service endpoint for Key Vault on the VM's subnet only routes traffic to the Key Vault's public endpoint via the Azure backbone, but it does not prevent the Key Vault from being accessible over the public internet, and it does not use a private IP address; a managed identity alone does not enforce network isolation. Option D is wrong because assigning a system-assigned managed identity and granting it access to Key Vault only handles authentication and authorization; it does not address network-level isolation or prevent traffic from leaving the Azure network.

71
MCQmedium

Your company uses Azure Blob Storage to store sensitive documents. You need to prevent data exfiltration by ensuring that all access to the storage account is through Microsoft's private network. What should you configure?

A.Apply a network security group (NSG) to the subnet with a deny rule for internet traffic.
B.Create a private endpoint for the storage account and disable public network access.
C.Set the firewall to deny all and add a rule to allow only your VNet's public IP.
D.Enable service endpoints and configure a service endpoint policy.
AnswerB

A private endpoint places the storage account on a private IP inside your VNet, and all requests to that IP are forwarded over Microsoft's backbone through Private Link, never the public internet. Disabling public network access then closes the storage account's externally visible endpoint, so only connections through the private endpoint are successful. This combination gives both private connectivity and exfiltration protection because the resource is no longer routable from any public source.

Why this answer

Creating a private endpoint for the storage account assigns it a private IP from your virtual network, and disabling public network access ensures that all traffic to the storage account is routed through Microsoft's backbone network, preventing data exfiltration over the public internet. This configuration effectively isolates the storage account to your private network, meeting the requirement to block all public access.

Exam trap

The trap here is that candidates often confuse service endpoints (which still leave the public endpoint active) with private endpoints (which fully remove public access), leading them to choose option D or C, thinking they have achieved private network access when they have not.

How to eliminate wrong answers

Option A is wrong because an NSG deny rule for internet traffic on the subnet does not prevent direct access to the storage account's public endpoint from other sources (e.g., on-premises or other VNets) and does not force traffic through Microsoft's private network. Option C is wrong because setting the firewall to deny all and allowing only your VNet's public IP still exposes the storage account to the public internet via its public endpoint, and a public IP is not private; this does not ensure access is through Microsoft's private network. Option D is wrong because service endpoints provide direct connectivity from a VNet to Azure services over the Microsoft backbone but still leave the storage account's public endpoint enabled, allowing potential data exfiltration if the firewall is misconfigured or bypassed.

72
MCQmedium

A company stores sensitive documents in an Azure Blob Storage account. They have enabled infrastructure encryption and configured the storage account to use a customer-managed key stored in Azure Key Vault for encryption at rest. Despite this, newly uploaded blobs are still encrypted with Microsoft-managed keys. What is the most likely cause?

A.The Key Vault is in a different Azure region than the storage account.
B.The storage account does not have a system-assigned managed identity enabled.
C.A default encryption scope is configured on the blob container that uses a Microsoft-managed key.
D.The customer-managed key in Key Vault is disabled or expired.
AnswerC

Encryption scopes can be set at the container level. A default encryption scope overrides the storage account-level encryption. If the scope uses Microsoft-managed keys, new blobs in that container will not use the customer-managed key.

Why this answer

When a default encryption scope is set on a blob container, it overrides the storage account's encryption settings for all blobs uploaded to that container. Even if the storage account is configured with a customer-managed key (CMK), the container-level encryption scope with a Microsoft-managed key takes precedence, causing new blobs to be encrypted with Microsoft-managed keys instead.

Exam trap

The trap here is that candidates assume the storage account-level CMK setting applies uniformly to all blobs, but they overlook that encryption scopes at the container level can override that setting, causing a silent fallback to Microsoft-managed keys.

How to eliminate wrong answers

Option A is wrong because Azure Key Vault and the storage account can be in different regions; cross-region CMK is supported as long as the Key Vault is in the same Azure Active Directory tenant. Option B is wrong because a system-assigned managed identity is not required for CMK; a user-assigned managed identity can be used, or the storage account can use its own identity implicitly when granted access to Key Vault via access policies or RBAC. Option D is wrong because if the customer-managed key were disabled or expired, the storage account would fail to encrypt or decrypt blobs, resulting in errors (e.g., 403 Forbidden) rather than silently falling back to Microsoft-managed keys.

73
Multi-Selecteasy

Which TWO database-level security features are available in Azure SQL Database to protect sensitive data?

Select 2 answers
A.Azure Information Protection
B.Always Encrypted
C.Dynamic Data Masking
D.Azure AD authentication
E.Azure Disk Encryption
AnswersB, C

Always Encrypted is a client-side encryption technology that protects sensitive data at the column level within Azure SQL Database. The database engine stores and processes ciphertext, while the encryption keys are held by the client application, so plaintext is never exposed to the database service. This makes it a true database-level data protection feature, purpose-built to prevent even database administrators from seeing raw sensitive values.

Why this answer

Always Encrypted (B) is correct because it is a database-level feature in Azure SQL Database that encrypts sensitive columns at the client side, keeping data encrypted at rest, in transit, and in memory, with the encryption keys never revealed to the database engine. Dynamic Data Masking (C) is also correct because it is a database-level feature that limits exposure of sensitive data by masking it in query results for non-privileged users without altering the underlying data. Azure Information Protection (A) is a classification and labeling service for documents and emails, not a database-level SQL security feature.

Azure AD authentication (D) is an identity/authentication mechanism for connecting to Azure SQL Database, not a data-protection feature for sensitive columns. Azure Disk Encryption (E) encrypts the underlying OS and data disks of VMs, so it does not apply to Azure SQL Database's database-level security.

Exam trap

The trap here is that candidates often confuse Azure Information Protection (a document-level classification tool) with database-level column encryption, or they mistakenly think Azure AD authentication or Disk Encryption directly protect sensitive data within the database tables.

74
MCQeasy

You are a security engineer for a healthcare company that stores patient records in an Azure Storage account. A compliance requirement mandates that all data in the storage account be encrypted at rest using a key that the company controls and can revoke at any time. The storage account is currently configured with Microsoft-managed keys for encryption. You need to change the encryption key management to meet the compliance requirement. What should you do first?

A.Create an Azure Key Vault and generate a customer-managed key, then configure the storage account to use that key for encryption.
B.Enable Azure Disk Encryption on the storage account to use customer-managed keys.
C.Enable Secure transfer required on the storage account to enforce encryption in transit.
D.Configure the storage account to use infrastructure encryption with Microsoft-managed keys.
AnswerA

Azure Storage supports server-side encryption with customer-managed keys stored in Azure Key Vault. To meet the requirement of using a company-controlled key that can be revoked, you must create a Key Vault, generate a key, and then update the storage account's encryption settings to use that key. This gives the organization full control over the encryption key lifecycle, including rotation and revocation, satisfying the compliance mandate.

Why this answer

To meet the requirement of encrypting data at rest with a customer-managed key, you must create an Azure Key Vault, generate a key, and configure the storage account to use that key for encryption. This ensures the organization controls the key lifecycle, including revocation. Other options either address different encryption aspects (in-transit) or use Microsoft-managed keys, which do not provide the required control.

Exam trap

The trap here is confusing encryption in transit (Secure transfer required) or infrastructure encryption with customer-managed encryption at rest.

75
MCQhard

Refer to the exhibit. You are analyzing the Always Encrypted configuration for an Azure SQL Database. The SSN column uses randomized encryption, and the CreditCard column uses deterministic encryption. Which statement is true regarding querying these columns?

A.Both columns support equality searches.
B.Only the CreditCard column supports equality searches.
C.Both columns support pattern matching with LIKE.
D.Only the SSN column supports point lookups.
AnswerB

Correct. The CreditCard column uses deterministic encryption, which with the same plaintext and column encryption key always yields the same ciphertext, enabling SQL Server to perform equality comparisons and exact-match point lookups directly on the encrypted column. SSN, by contrast, uses randomized encryption, so the same value encrypts differently each time and cannot be compared for equality without client-side decryption. Therefore only CreditCard supports equality searches.

Why this answer

Deterministic encryption always generates the same ciphertext for a given plaintext, enabling equality comparisons and point lookups. Randomized encryption produces different ciphertexts each time, preventing any equality or pattern-matching operations. Therefore, only the CreditCard column (deterministic) supports equality searches.

Exam trap

The trap here is that candidates assume randomized encryption still supports equality searches because it is still 'encryption,' but the key distinction is that deterministic encryption is the only mode that allows server-side equality comparisons.

How to eliminate wrong answers

Option A is wrong because randomized encryption (SSN) does not support equality searches; only deterministic encryption does. Option C is wrong because neither randomized nor deterministic encryption supports pattern matching with LIKE, as encryption operates on the entire value and does not allow substring operations. Option D is wrong because the SSN column uses randomized encryption, which does not support point lookups (equality searches); only the CreditCard column (deterministic) supports them.

Page 1 of 2 · 137 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Secure Compute Storage Db questions.