DP-900 Practice Question: Identify considerations for relational data on Azure
Which TWO are valid ways to secure data in transit for an Azure SQL Database?
⚠ Common exam trap
Candidates often confuse encryption at rest (TDE) or column-level encryption (Always Encrypted) with transport encryption, leading them to select options that protect data at different layers rather than data in transit.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use the 'Encrypt connection' setting in connection strings
Option A is correct because the 'Encrypt connection' setting in a connection string (e.g., Encrypt=True;TrustServerCertificate=False) forces the client driver to negotiate an encrypted channel to Azure SQL Database, protecting data in transit. Option B is correct because requiring TLS 1.2 for client connections ensures that only modern, secure transport encryption is used between the client and the database, preventing downgrade to weaker protocols. Option C is not correct because Transparent Data Encryption protects data at rest by encrypting database files, not data moving over the network. Option D is not correct because firewall rules restrict which IP addresses can reach the server but do not encrypt the traffic itself. Option E is not correct because Always Encrypted protects sensitive columns at rest and in memory on the client side, not the transport channel.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Use the 'Encrypt connection' setting in connection strings
Why this is correct
The 'Encrypt connection' setting in connection strings instructs the client driver to negotiate TLS encryption for the entire connection to Azure SQL Database. When Encrypt=True and TrustServerCertificate=False are used, the driver validates the server certificate and creates an encrypted channel, preventing eavesdropping and man-in-the-middle attacks on all data sent between the application and the database. This is a direct, connection-level mechanism for securing data in transit.
- ✓
Require TLS 1.2 for client connections
Why this is correct
Requiring TLS 1.2 for client connections establishes a server-side policy that rejects older, weaker protocols like TLS 1.0 and 1.1. Azure SQL Database and Azure Synapse Analytics let administrators set the Minimum TLS Version to 1.2, ensuring every client must use a modern cipher suite with strong encryption. This prevents protocol downgrade attacks and guarantees that the TLS handshake and all subsequent traffic are protected.
- ✗
Enable Transparent Data Encryption (TDE)
Why it's wrong here
Transparent Data Encryption (TDE) performs automatic, real-time encryption of database files, backups, and transaction logs at the storage layer. It is designed to protect data at rest from physical theft or unauthorized access to storage media, not from network interception. With TDE, the data is decrypted internally by the database engine before being sent over the network, so without TLS it would still travel in plaintext.
- ✗
Configure firewall rules to allow only specific IPs
Why it's wrong here
Firewall rules in Azure restrict which client IP addresses can establish connections to a data service, acting as a network-level access control list rather than an encryption mechanism. They determine who can reach the endpoint, but they do not modify or protect the data as it crosses the network. A packet captured between the client and Azure would still be readable without TLS, so firewall rules are irrelevant to securing data in transit.
- ✗
Use Always Encrypted
Why it's wrong here
Always Encrypted uses client-side encryption for specific database columns, with encryption keys held by the application, so those column values are never exposed to the database server in plaintext. It protects designated sensitive fields during transmission, but it does not encrypt the entire communications stream or all data in the database. Therefore, it is not the primary method for securing all data in transit for an Azure database connection.
Go deeper
Related to this question
Learn chapter
Transparent Data Encryption (TDE) in Azure SQL
Key term
Data
Data is raw, unprocessed information, like numbers, words, or measurements, that can be stored, processed, and analyzed by computers.
Key term
Azure SQL Database
Azure SQL Database is a fully managed relational database-as-a-service (DBaaS) in Microsoft Azure, based on the SQL Server engine, that handles scaling, backups, patching, and high availability automatically.
About these practice questions
This DP-900 question is part of Courseiva's 851-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DP-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-900 exam.