Courseiva

Enforce Secure Configuration of Azure SQL Database with Azure Policy

Which TWO Azure policies should you assign to enforce secure configuration of Azure SQL Database? (Select two.)

Quick Answer

The answer is to assign the Azure Policy built-in initiatives for enabling Auditing on Azure SQL Database and for configuring Firewall and virtual network settings. Auditing is correct because it captures all database events and writes them to an audit log in your Azure storage account, Log Analytics workspace, or Event Hubs, providing a fundamental security control for compliance and forensic analysis by recording who did what and when. The firewall policy is equally essential as it enforces network-level access restrictions, preventing unauthorized connections from public endpoints. On the Microsoft Cybersecurity Architect exam, this pairing tests your understanding that secure configuration requires both detective controls (auditing) and preventive controls (network isolation), with a common trap being to select only one policy or to confuse auditing with threat detection. Remember the mnemonic “Audit the Access, Lock the Network” to recall that you need both event logging and firewall rules to enforce secure configuration of Azure SQL Database with Azure Policy.

⚠ Common exam trap

Candidates often confuse SQL Server VM policies (like TDE or SQL Server-level audit settings) with Azure SQL Database policies, or they mistakenly apply storage account policies to SQL Database, which is a separate Azure service with its own security controls.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Ensure that 'Auditing' is set to 'On' for SQL Database

Option A is correct because the built-in Azure Policy 'Auditing on SQL Database should be enabled' enforces that auditing is set to 'On' for Azure SQL Database, ensuring database activity is logged for security and compliance monitoring. Option D is correct because the policy 'Firewall and virtual network settings for SQL Database should be configured' enforces that Azure SQL Database has network-level access controls (firewall rules or virtual network service endpoints/private endpoints) in place, restricting access to authorized networks only. Option B is incorrect because it targets TDE on SQL Server running on VMs (IaaS), not Azure SQL Database (PaaS), so it does not apply to this scenario. Option C is incorrect because it audits the SQL Server-level audit setting rather than enforcing a secure configuration on Azure SQL Database itself. Option E is incorrect because it concerns secure transfer for storage accounts, which is unrelated to Azure SQL Database configuration.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Ensure that 'Auditing' is set to 'On' for SQL Database

    Why this is correct

    Enabling SQL Database auditing satisfies the secure-configuration requirement by recording all database events to a storage, Log Analytics or Event Hub destination, giving the detective evidence trail that Azure Policy's Auditing effect enforces at scale across every server and database in scope.

  • ✗

    Ensure that 'TDE' is enabled for SQL Server VMs

    Why it's wrong here

    TDE on SQL Server VMs is configured inside the guest OS via IaaS tooling, so an Azure SQL Database policy cannot enforce it. It is tempting because TDE does protect database files at rest, but the correct policies target the PaaS SQL Database service, not virtual machines.

  • ✗

    Audit SQL Server level audit setting

    Why it's wrong here

    This policy audits the server-level audit setting rather than enforcing a secure configuration, so it detects but does not prevent misconfiguration. It is tempting because auditing underpins compliance monitoring, yet the question asks for policies that enforce security controls on Azure SQL Database.

  • ✓

    Ensure that 'Firewall and virtual network settings' for SQL Database are configured

    Why this is correct

    Configuring firewall and virtual network settings satisfies the network-isolation constraint by denying public Azure service access and permitting only approved IP ranges, private endpoints or subnet delegations, so Azure Policy blocks any SQL server left reachable from the open internet.

  • ✗

    Ensure secure transfer to storage accounts is enabled

    Why it's wrong here

    Secure transfer applies to Azure Storage account endpoints, not to Azure SQL Database connections, so it cannot enforce SQL security configuration. It is tempting because both are data services with encryption settings, but the correct policies scope to SQL Database rather than storage accounts.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SC-100

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Your organization uses Azure SQL Database with Azure AD authentication. You need to ensure that database administrators (DBAs) can only perform management tasks from a specific Azure region and only during business hours. Which solution should you use?

hard
  • ✓ A.Azure AD Conditional Access policies
  • B.Azure RBAC with custom roles
  • C.Azure Policy with custom policy
  • D.Azure SQL Database firewall rules

Why A: Azure AD Conditional Access policies are the correct solution because they can enforce both location-based (named locations/regions) and time-based (sign-in frequency, or via authentication context combined with Conditional Access) conditions on sign-ins to Azure SQL Database when Azure AD authentication is used. This directly satisfies the requirement that DBAs perform management tasks only from a specific Azure region and only during business hours. Azure RBAC with custom roles (B) only controls what actions a principal can perform, not when or from where they sign in. Azure Policy (C) governs resource configuration and compliance, not user sign-in conditions. Azure SQL Database firewall rules (D) restrict network access by IP range but cannot enforce business-hours time restrictions.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.