AZ-500 Secure compute, storage, and databases Practice Question
You are the Azure Security Engineer for a company that uses Azure SQL Database. A recent security audit requires that all connections to the database be encrypted and that the database reject any unencrypted connections. You need to enforce this requirement with the least administrative effort. What should you do?
⚠ Common exam trap
Test-takers frequently confuse data-at-rest encryption features like TDE or Always Encrypted with transport encryption enforcement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable the 'Enforce SSL connection' setting on the Azure SQL Database server.
The 'Enforce SSL connection' setting on the Azure SQL Database server forces all connections to use TLS encryption. When enabled, any attempt to connect without encryption is rejected. This directly satisfies the requirement to encrypt all connections and reject unencrypted ones, and it requires only a single configuration change.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure a firewall rule on the Azure SQL Database server to allow only connections from specific IP addresses.
Why it's wrong here
Firewall rules restrict which IP addresses can connect, but they do not enforce encryption. An allowed client could still connect without TLS. This does not meet the requirement to reject unencrypted connections. Firewall rules are a network security control, not a transport encryption control.
- ✗
Implement Always Encrypted on all sensitive columns in the database.
Why it's wrong here
Always Encrypted protects data at rest and in use by encrypting specific columns, but it does not enforce encryption of the connection between the client and the server. It is possible to have Always Encrypted columns and still connect over an unencrypted channel. This option addresses data confidentiality, not connection encryption.
- ✗
Enable Transparent Data Encryption (TDE) on the Azure SQL Database.
Why it's wrong here
TDE encrypts the database files at rest, but it does not affect the encryption of client connections. Connections can still be unencrypted. TDE is enabled by default and is not the mechanism to enforce encrypted connections. This option confuses data-at-rest encryption with transport encryption.
- ✓
Enable the 'Enforce SSL connection' setting on the Azure SQL Database server.
Why this is correct
Azure SQL Database provides a server-level setting called 'Enforce SSL connection' (or 'Require secure transfer' in some interfaces). When enabled, the server rejects any connection that is not encrypted with TLS. This is a simple configuration change that enforces encryption for all connections to the database, meeting the audit requirement with minimal effort.
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.