Courseiva

AZ-500 Secure compute, storage, and databases Practice Question

You are a security engineer for a company that uses Azure SQL Database. The database contains sensitive financial data and is currently encrypted with Transparent Data Encryption (TDE) using a service-managed key. A new policy requires that the TDE protector be a customer-managed key stored in Azure Key Vault, and that the key be automatically rotated every 90 days. You have created an Azure Key Vault and generated a key. What should you do next to meet the policy?

⚠ Common exam trap

The trap here is thinking that Always Encrypted or backup encryption settings are needed for TDE with customer-managed keys.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure the SQL server's TDE protector to use the customer-managed key from Key Vault, and enable auto-rotation on the key.

To meet the policy, you must set the Azure SQL logical server's TDE protector to the customer-managed key stored in Azure Key Vault. Azure Key Vault supports automatic key rotation, which can be configured for 90-day rotation. This ensures the database is encrypted with a customer-managed key and the key is rotated regularly. Other options either address different features (Always Encrypted) or involve unnecessary migration.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a new Azure SQL Database with the customer-managed key as the TDE protector, and migrate the data.

    Why it's wrong here

    You can change the TDE protector on an existing Azure SQL Database without recreating it. Creating a new database and migrating data is unnecessary and disruptive. The requirement can be met by updating the existing server's TDE protector to use the customer-managed key. Therefore, this approach is not the correct next step.

  • ✓

    Configure the SQL server's TDE protector to use the customer-managed key from Key Vault, and enable auto-rotation on the key.

    Why this is correct

    To use a customer-managed key for TDE, you must configure the Azure SQL logical server to use the key from Key Vault as the TDE protector. Azure Key Vault supports automatic key rotation, which can be set to rotate every 90 days. This satisfies both the requirement for customer-managed key and automatic rotation. The SQL server must have a managed identity with appropriate permissions to access the key vault.

  • ✗

    Enable Always Encrypted on the database and use the customer-managed key for column encryption.

    Why it's wrong here

    Always Encrypted is designed to protect individual columns, not the entire database at rest. The policy specifically requires TDE with a customer-managed key. Always Encrypted uses column encryption keys and column master keys, which are different from the TDE protector. Enabling Always Encrypted would not change the TDE protector and would not meet the requirement for TDE with a customer-managed key.

  • ✗

    Store the customer-managed key in Azure Key Vault and configure the database to use it for backup encryption.

    Why it's wrong here

    Backup encryption for Azure SQL Database is handled by TDE, not by a separate backup encryption setting. Configuring the key for backup encryption is not a valid operation. The correct approach is to set the TDE protector to the customer-managed key, which will also protect backups. This option misinterprets how TDE and backups interact.

About these practice questions

Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.