Courseiva

SC-100 Practice Question: Design security solutions for applications and data

A financial services company is designing a security strategy for its Azure SQL Database. The database contains sensitive financial data. The company requires that all connections to the database be encrypted and that the database be protected against SQL injection attacks. Additionally, they need to monitor and audit all database activities for compliance. Which Azure features should the security architect recommend?

⚠ Common exam trap

The trap here is equating network-level protections like firewall rules or Private Link with application-layer SQL injection prevention, which requires threat detection and secure coding practices.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enforce TLS 1.2 for connections, enable Azure Defender for SQL, and configure auditing to Azure Monitor logs.

The requirements are encrypted connections, SQL injection protection, and auditing. Enforcing TLS 1.2 ensures connections are encrypted. Azure Defender for SQL provides advanced threat protection that detects and alerts on SQL injection attempts. Configuring auditing to Azure Monitor logs centralizes monitoring and auditing. Together, these features meet the security and compliance needs for the Azure SQL Database.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use Azure Private Link to connect to the database, enable Always Encrypted for sensitive columns, and use Azure Policy to enforce auditing.

    Why it's wrong here

    Azure Private Link secures network connectivity but does not encrypt connections at the application layer; it uses private IPs. Always Encrypted protects data at rest and in use but does not prevent SQL injection. Azure Policy can enforce auditing configuration but does not itself monitor activities. This option does not fully satisfy the encrypted connection and SQL injection protection requirements.

  • ✗

    Configure Azure SQL Database firewall rules to restrict IP addresses, enable Transparent Data Encryption (TDE), and use Azure Monitor for auditing.

    Why it's wrong here

    Firewall rules restrict network access but do not prevent SQL injection from allowed clients. TDE encrypts data at rest, not connections. Azure Monitor can collect logs, but it is not a dedicated auditing solution for SQL Database. This option misses connection encryption and SQL injection mitigation, so it does not meet all requirements.

  • ✓

    Enforce TLS 1.2 for connections, enable Azure Defender for SQL, and configure auditing to Azure Monitor logs.

    Why this is correct

    Enforcing TLS 1.2 ensures encrypted connections. Azure Defender for SQL (part of Microsoft Defender for Cloud) provides vulnerability assessment and advanced threat protection, including detection of SQL injection attempts. Configuring auditing to Azure Monitor logs enables monitoring and auditing of database activities. This combination addresses all three requirements: encryption, SQL injection protection, and auditing.

  • ✗

    Enable Azure SQL Database auditing to a storage account, configure Advanced Threat Protection, and enforce TLS 1.2 for connections.

    Why it's wrong here

    Auditing and Advanced Threat Protection are valuable, but this option does not address SQL injection protection. Advanced Threat Protection detects anomalous activities but does not block SQL injection. Enforcing TLS 1.2 ensures encrypted connections, but without a web application firewall or parameterized queries, SQL injection remains a risk. This option is incomplete for the stated requirements.

About these practice questions

One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.