SC-100 Practice Question: Design security solutions for applications and data
A large financial services company is migrating its customer-facing web application to Azure. The application handles sensitive personal data and must comply with PCI DSS. The solution will use Azure App Service (Linux) with a custom container, Azure SQL Database, and Azure Redis Cache. The security architect mandates that all data in transit be encrypted using the latest TLS version, and that the application must be protected against common web vulnerabilities. The company also wants to ensure that only authenticated users can access the Redis cache. Users will authenticate via Microsoft Entra ID. The operations team needs to be able to monitor for SQL injection attempts and anomalous access patterns. You need to design the security configuration. Which of the following is the most comprehensive approach that meets all requirements?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure App Service to enforce TLS 1.2 as minimum. Deploy Azure Application Gateway with WAF enabled in front of App Service. Enable Microsoft Entra ID authentication for Azure Redis Cache. Enable Microsoft Defender for SQL for Azure SQL Database.
Azure App Service enforces TLS 1.2/1.3 by default. Azure WAF (Web Application Firewall) in front of App Service protects against OWASP Top 10. Microsoft Entra ID authentication for Redis Cache is supported via Microsoft Entra ID RBAC for Redis (currently in preview but available). Microsoft Defender for SQL detects SQL injection and anomalous access. Option A covers all requirements. Option B uses Application Gateway without WAF. Option C uses Redis firewall which doesn't enforce authentication. Option D uses Azure Front Door without WAF.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Configure App Service to enforce TLS 1.2 as minimum. Deploy Azure Application Gateway with WAF enabled in front of App Service. Enable Microsoft Entra ID authentication for Azure Redis Cache. Enable Microsoft Defender for SQL for Azure SQL Database.
Why this is correct
This is the correct defense-in-depth approach. Enforcing TLS 1.2 as the minimum on App Service guarantees strong transport encryption for all client communications. Deploying Azure Application Gateway with WAF enabled in front of App Service provides an OWASP Top 10 web application firewall that inspects and blocks malicious L7 traffic, preventing SQL injection, XSS, and other common attacks. Enabling Microsoft Entra ID authentication for Redis Cache replaces key-based access with managed identity, supporting passwordless, conditional access policies. Microsoft Defender for SQL for Azure SQL Database adds threat detection, vulnerability assessment, and anomaly alerts, covering the database tier comprehensively.
- ✗
Use Azure Front Door with custom domain and enforce TLS 1.2. Configure IP firewall on Redis Cache. Use Azure SQL Database with VNet service endpoints.
Why it's wrong here
This option fails to secure the web application from application-layer attacks because Azure Front Door alone does not apply a WAF policy; without a configured web application firewall, attacks like SQL injection reach App Service. Redis IP firewall only restricts network access by IP address—it does not authenticate users or applications, allowing any attacker who spoofs an allowed IP or uses a compromised resource to access the cache. VNet service endpoints for Azure SQL Database merely isolate network traffic and do not provide threat detection or vulnerability management, leaving the database prone to undetected malicious activity. The combination also lacks any SQL-specific monitoring, so the solution is incomplete.
- ✗
Deploy App Service with HTTPS only enabled. Use Azure API Management with WAF. Use Redis Cache with access keys. Enable SQL audit logging.
Why it's wrong here
Enabling 'HTTPS only' on App Service simply redirects HTTP to HTTPS and does not enforce a minimum TLS version, leaving older, weaker protocols such as TLS 1.0/1.1 enabled, which violates security best practices. Azure API Management does not inherently include a WAF; a WAF must be placed in front or enabled on an upstream gateway like Application Gateway, so this setup leaves the App Service exposed to web attacks. Redis access keys are pre-shared secrets, not user authentication, and without Microsoft Entra ID integration the client is not verified beyond possessing the key. SQL audit logging records queries but offers no active threat detection or alerts, unlike Microsoft Defender for SQL, so the database tier remains unprotected against emerging threats.
- ✗
Enable TLS 1.3 on App Service. Use Azure CDN with WAF. Configure Redis Cache with a firewall rule allowing only App Service outbound IPs.
Why it's wrong here
While TLS 1.3 is a strong encryption protocol, enabling it alone does not address other attack vectors, and Azure CDN's WAF is a limited, rules-based engine tailored for content delivery, not a full layer-7 web application firewall for dynamic app protection—it lacks the depth of Application Gateway WAF. Restricting Redis Cache by a firewall rule that allows only App Service outbound IPs is a network-level control that does not authenticate distinct users; App Service outbound IPs are shared and can change, so this is unreliable and still permits any client within an allowed IP range. The option completely omits any form of database threat detection or vulnerability assessment for SQL Database, leaving the most sensitive asset unmonitored. Missing Microsoft Entra ID authentication for Redis means the cache remains vulnerable to key compromise.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.