AZ-500 Secure compute, storage, and databases Practice Question
Which TWO database-level security features are available in Azure SQL Database to protect sensitive data?
⚠ Common exam trap
Many candidates confuse Azure Information Protection (a document-level classification tool) with database-level column encryption, or they mistakenly think Microsoft Entra ID authentication or Disk Encryption directly protect sensitive data within the database tables.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Always Encrypted
Always Encrypted (B) is correct because it is a database-level feature in Azure SQL Database that encrypts sensitive columns at the client side, keeping data encrypted at rest, in transit, and in memory, with the encryption keys never revealed to the database engine. Dynamic Data Masking (C) is also correct because it is a database-level feature that limits exposure of sensitive data by masking it in query results for non-privileged users without altering the underlying data. Azure Information Protection (A) is a classification and labeling service for documents and emails, not a database-level SQL security feature. Microsoft Entra ID authentication (D) is an identity/authentication mechanism for connecting to Azure SQL Database, not a data-protection feature for sensitive columns. Azure Disk Encryption (E) encrypts the underlying OS and data disks of VMs, so it does not apply to Azure SQL Database's database-level security.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Azure Information Protection
Why it's wrong here
Azure Information Protection is an information governance and classification service for documents and emails, not a database-level security control. It applies sensitivity labels and policy templates, but it does not encrypt columns, mask query results, or enforce row-level restrictions in Azure SQL Database. It may integrate with broader data governance, yet it cannot be configured as a feature inside the database itself.
- ✓
Always Encrypted
Why this is correct
Always Encrypted is a client-side encryption technology that protects sensitive data at the column level within Azure SQL Database. The database engine stores and processes ciphertext, while the encryption keys are held by the client application, so plaintext is never exposed to the database service. This makes it a true database-level data protection feature, purpose-built to prevent even database administrators from seeing raw sensitive values.
- ✓
Dynamic Data Masking
Why this is correct
Dynamic Data Masking limits exposure of sensitive information by disguising data in query results according to defined masking rules, such as partial email addresses or credit card numbers. It operates at the database level and can be applied to specific columns while leaving the underlying data intact for authorized users. Because it does not encrypt data, it complements rather than replaces encryption features like Always Encrypted.
- ✗
Microsoft Entra ID authentication
Why it's wrong here
Microsoft Entra ID authentication controls how principals are identified and granted access to the database, but it does not protect the data itself once a user is authenticated. It enables multifactor authentication and conditional access, yet it is an access-control mechanism rather than a database-level security feature that encrypts or masks data. Therefore it is not one of the requested database-level data protection features.
- ✗
Azure Disk Encryption
Why it's wrong here
Azure Disk Encryption is designed for IaaS virtual machines, encrypting OS and data disks with BitLocker or DM-Crypt, and is not applicable to Azure SQL Database's managed storage stack. Azure SQL Database relies on Transparent Data Encryption for at-rest protection, and disk-level encryption is not a database-level feature you configure inside the PaaS service. Thus it is not a valid answer.
Go deeper
Related to this question
About these practice questions
One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.