Courseiva

SC-100 Practice Question: Design security solutions for applications and data

A company is deploying a new application that will store sensitive customer data in Azure SQL Database. The security team requires that all data at rest be encrypted using a customer-managed key stored in Azure Key Vault. Additionally, they need to ensure that the database can be restored to a point in time and that the encryption key is rotated every 90 days. Which combination of features should you configure?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable TDE with customer-managed keys in Azure Key Vault and configure automatic key rotation.

Option D is correct because Transparent Data Encryption (TDE) with customer-managed keys (CMK) in Azure Key Vault encrypts Azure SQL Database data at rest, and TDE supports point-in-time restore (PITR) via automated backups while allowing automatic key rotation through the Key Vault key rotation policy. Configuring TDE with a CMK satisfies the requirement that the encryption key be customer-managed and rotated every 90 days. Option A is wrong because service-managed keys do not meet the customer-managed key requirement, and Azure Policy cannot itself rotate TDE protector keys. Option B is wrong because Always Encrypted protects data in use and in transit at the client, not data at rest as required, and manual rotation does not meet the 90-day automated rotation need. Option C is wrong because Azure Storage Service Encryption applies to Azure Storage, not Azure SQL Database, and soft delete is a Key Vault data-protection feature, not a database encryption solution.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable TDE with service-managed keys and use Azure Policy to enforce rotation.

    Why it's wrong here

    Service-managed keys for Transparent Data Encryption are rotated automatically by Microsoft on an internal schedule, offering no customer visibility or control over the rotation cadence. Azure Policy can enforce that TDE is enabled or that a customer-managed key is specified, but it cannot trigger or define rotation for service-managed keys because Azure manages the complete key lifecycle. Therefore, this configuration fails to meet the requirement for customer-controlled, automated key rotation.

  • ✗

    Use Always Encrypted with column master key in Azure Key Vault and manual rotation.

    Why it's wrong here

    Always Encrypted is a client-side encryption technology that protects sensitive columns by encrypting data in the application layer before it reaches the database, leaving the bulk of the database unencrypted at rest. Even with the column master key stored in Azure Key Vault, rotation is a manual process involving key creation, column master key and column encryption key updates, and a data re-encryption operation. This approach neither encrypts the entire database nor provides automated rotation, so it does not satisfy the stated requirement.

  • ✗

    Use Azure Storage Service Encryption with customer-managed keys and enable soft delete.

    Why it's wrong here

    Azure Storage Service Encryption with customer-managed keys encrypts data at rest in Azure Blob Storage or other storage services, but it has no effect on an Azure SQL database's physical data files. SQL Database encryption at rest is governed by Transparent Data Encryption, not by Azure Storage's encryption layer. Enabling soft delete on a storage account helps protect storage blobs from accidental deletion, but it is irrelevant to SQL database encryption and key rotation.

  • ✓

    Enable TDE with customer-managed keys in Azure Key Vault and configure automatic key rotation.

    Why this is correct

    Transparent Data Encryption with customer-managed keys in Azure Key Vault encrypts the entire SQL database by using a symmetric Database Encryption Key (DEK) that is itself protected by an asymmetric TDE protector stored in the vault. You can enable automatic rotation on the TDE protector, which configures Azure SQL to automatically use the latest version of the key from Azure Key Vault without any manual intervention. This gives the organization full control over key management and satisfies the requirement for automated, periodic rotation.

About these practice questions

This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.