AZ-500 Secure compute, storage, and databases Practice Question
You need to enable transparent data encryption (TDE) for an Azure SQL Managed Instance. What is the prerequisite?
⚠ Common exam trap
Test-takers frequently assume TDE requires manual setup or a key vault, but Azure SQL Managed Instance enables TDE by default with a service-managed key, making options like D a common distractor for those familiar with on-premises or IaaS-based SQL Server configurations.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
No additional configuration is needed; TDE is enabled by default.
Transparent Data Encryption (TDE) is enabled by default for Azure SQL Managed Instance. When you create a new managed instance, TDE is automatically turned on using a service-managed key, so no additional configuration is required. This default behavior ensures data at rest is encrypted without any prerequisite steps from the user.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure a backup policy for the managed instance.
Why it's wrong here
Configuring a backup policy on the managed instance controls point-in-time restore retention and long-term backup retention; it does not affect whether Transparent Data Encryption is active. TDE is a database-level encryption feature implemented in the storage engine, encrypting data, log, and backup files as they are written to disk. A backup policy may ensure recoverability, but it neither enables nor disables TDE, and it is not a prerequisite for the encryption to be on by default.
- ✗
Enable a service endpoint for Azure SQL.
Why it's wrong here
Enabling a service endpoint for Azure SQL establishes a secure and optimized connection from a virtual network to the SQL service by extending the VNet identity to the service. This is a network-layer configuration that controls connectivity and firewall rules, not data-at-rest encryption. TDE operates independently of network access; it encrypts database files on persistent storage, so a service endpoint has no bearing on whether TDE is already enabled.
- ✓
No additional configuration is needed; TDE is enabled by default.
Why this is correct
Azure SQL Managed Instance is created with Transparent Data Encryption already enabled by default, using a service-managed key that Microsoft rotates automatically. No configuration, such as creating a key or modifying settings, is required on the managed instance to activate TDE. The encryption of data and log files happens automatically in real time, making this the correct choice because the question's requirement is already satisfied.
- ✗
Create an Azure Key Vault and configure a customer-managed key.
Why it's wrong here
Creating an Azure Key Vault and configuring a customer-managed key is an optional 'bring your own key' (BYOK) scenario for TDE, not a step required to enable TDE. When you use a customer-managed key, Azure doesn't automatically rotate the key and you must grant access via a managed identity, but the default TDE state already uses a Microsoft-managed key (service-managed key). Therefore, while this is a valid way to customize TDE, it is unnecessary for simply having TDE enabled.
Go deeper
Related to this question
About these practice questions
One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.