Courseiva

How to Encrypt Azure SQL Database at Rest and in Transit

Your organization is designing a new application that will store sensitive customer data in Azure Cosmos DB. You need to ensure that data at rest is encrypted using a customer-managed key (CMK) stored in Azure Key Vault. What should you configure?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure a customer-managed key in Azure Key Vault and assign it to the Cosmos DB account.

Option D is correct because Azure Cosmos DB supports encryption at rest with customer-managed keys (CMKs), which are created and stored in Azure Key Vault and then assigned to the Cosmos DB account via its encryption settings. This satisfies the requirement to control the key used for data-at-rest encryption rather than relying on Microsoft-managed keys. Option A is incorrect because Transparent Data Encryption (TDE) is an Azure SQL feature, not a Cosmos DB configuration. Option B is incorrect because Azure Storage Service Encryption (SSE) applies to Azure Storage services, not Cosmos DB. Option C is incorrect because Always Encrypted is an Azure SQL Database/client-side encryption feature and does not configure CMK encryption for Cosmos DB.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable Transparent Data Encryption (TDE) on the Cosmos DB account.

    Why it's wrong here

    Transparent Data Encryption (TDE) is a SQL Server and Azure SQL Database feature that performs real-time I/O-level encryption of data files using a database encryption key. Azure Cosmos DB is a NoSQL database service that does not expose a TDE setting, and you cannot enable TDE on a Cosmos DB account. Cosmos DB encrypts data at rest by default with Microsoft-managed keys, so this option is not applicable.

  • ✗

    Enable Azure Storage Service Encryption (SSE) on the Cosmos DB account.

    Why it's wrong here

    Azure Storage Service Encryption (SSE) automatically encrypts data at rest for Azure Blob, Queue, Table, and File storage, not for PaaS database services like Cosmos DB. Though Cosmos DB does persist data on Azure Storage infrastructure internally, SSE settings are managed at the storage account level and cannot be toggled via the Cosmos DB account blade. Choosing SSE is therefore a mismatch of service boundaries; the actual Cosmos DB mechanism for bringing customer-controlled keys is customer-managed key configuration, not SSE.

  • ✗

    Use Always Encrypted with Azure SQL Database.

    Why it's wrong here

    Always Encrypted is a client-side encryption technology available in SQL Server, Azure SQL Database, and Azure SQL Managed Instance, where the database engine stores encrypted data but never sees the plaintext keys. This feature applies only to relational SQL engines and has no representation within the Cosmos DB resource model. While it protects column-level data for SQL workloads, it cannot be used to encrypt a Cosmos DB account or its data, making it an incorrect choice.

  • ✓

    Configure a customer-managed key in Azure Key Vault and assign it to the Cosmos DB account.

    Why this is correct

    To meet a bring-your-own-key (BYOK) requirement on Azure Cosmos DB, you must configure a customer-managed key in Azure Key Vault and associate it with the Cosmos DB account. This uses envelope encryption where the Key Vault key wraps the account's data encryption keys, allowing you to independently rotate, revoke, or audit key usage. You can establish this by assigning a key URI from Key Vault to the Cosmos DB account (typically via a managed identity and appropriate Key Vault access policy), which gives you control over at-rest encryption.

About these practice questions

This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.