Courseiva

AZ-500 Always Encrypted Practice Question

Which two security configurations should you apply to an Azure SQL Database to meet a requirement for data protection at rest and in transit?

⚠ Common exam trap

It's easy for candidates to confuse Transparent Data Encryption (TDE) with protecting data in transit, but TDE only encrypts data at rest (the database files and backups), not data moving between the client and server.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use Always Encrypted for sensitive columns.

Option B (Always Encrypted for sensitive columns) is correct because Always Encrypted protects sensitive data both at rest and in transit by keeping data encrypted on the client side, so the database engine never sees plaintext — the column encryption keys are never exposed to Azure SQL Database. Option C (Transparent Data Encryption, TDE) is correct because TDE performs real-time encryption and decryption of the database, backups, and transaction log files at rest using a symmetric database encryption key protected by a certificate stored in Azure Key Vault or the service-managed key store, satisfying the data-at-rest requirement. Option A (Microsoft Defender for Azure SQL) is not correct here because it is a threat detection and vulnerability assessment service, not a data encryption mechanism for protecting data at rest or in transit. Option D (firewall rules to allow only trusted IP addresses) is not correct because it is network access control, not encryption of data at rest or in transit. Option E (Azure SQL Auditing) is not correct because auditing tracks and logs database events for compliance and forensic purposes, but it does not encrypt or protect the data itself.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable Microsoft Defender for Azure SQL.

    Why it's wrong here

    Enable Microsoft Defender for Azure SQL: This provides security monitoring and threat detection, not data encryption at rest or in transit.

  • ✓

    Use Always Encrypted for sensitive columns.

    Why this is correct

    Use Always Encrypted for sensitive columns: Correct. It encrypts sensitive data both at rest and in transit by keeping encryption keys on the client side.

  • ✓

    Enable Transparent Data Encryption (TDE).

    Why this is correct

    Enable Transparent Data Encryption (TDE): Correct. TDE encrypts the database at rest, protecting data when stored on disk.

  • ✗

    Configure firewall rules to allow only trusted IP addresses.

    Why it's wrong here

    Configure firewall rules to allow only trusted IP addresses: Incorrect. This restricts network access but does not encrypt data at rest or in transit.

  • ✗

    Enable Azure SQL Auditing.

    Why it's wrong here

    Enable Azure SQL Auditing: Incorrect. Auditing logs database events but does not provide encryption.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.