SC-100 Design security solutions for infrastructure Practice Question
Exhibit
Refer to the exhibit.
```bicep
resource sqlServer 'Microsoft.Sql/servers@2021-11-01' = {
name: 'sql-${uniqueString(resourceGroup().id)}'
location: resourceGroup().location
properties: {
administratorLogin: 'adminuser'
administratorLoginPassword: 'P@ssw0rd1234'
minimalTlsVersion: '1.2'
publicNetworkAccess: 'Disabled'
}
}
```Refer to the exhibit. You are reviewing a Bicep template for deploying an Azure SQL Database server. Which security best practice is violated?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Administrator password is hardcoded in plain text.
The administrator password is hardcoded in plain text, which violates the security best practice of never embedding secrets directly in infrastructure-as-code templates. Hardcoded credentials in a Bicep file can be exposed through source control, deployment history, or template exports, so the password should instead be supplied via a secure parameter using Key Vault or a secure string parameter. Option A is not a violation because TLS 1.2 is the minimum acceptable version for Azure SQL Database. Option C is not a violation because disabling public network access is actually a recommended security hardening measure, typically paired with private endpoints. Option D is a weaker recommendation rather than the clear violation shown, since Microsoft Entra ID authentication is encouraged but the exposed plaintext password is the definitive security flaw.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Minimal TLS version is set to 1.2, which is acceptable.
Why it's wrong here
Setting the minimal TLS version to 1.2 is not a misconfiguration; it aligns with Microsoft's security baseline, which requires disabling legacy TLS 1.0 and 1.1. TLS 1.2 or higher is the industry-standard minimum for encrypted connections to Azure SQL and storage accounts. Therefore, this configuration is acceptable and should not be flagged as a best-practice violation in a Bicep template review.
- ✓
Administrator password is hardcoded in plain text.
Why this is correct
Hardcoding the administrator password as a plaintext string in the Bicep template is a critical security flaw. Anyone with read access to the template or the source control repository can extract the credential, and the secret is also exposed in deployment history. This violates Microsoft's recommendation that secrets must be stored in Azure Key Vault and referenced via the `keyVault` reference or `getSecret` function, or accepted as a secure parameter at deployment time.
- ✗
Public network access is disabled, which may affect connectivity.
Why it's wrong here
Disabling public network access is a deliberate security control that eliminates exposure to the internet, significantly reducing the attack surface. The template is designed for private connectivity, so the resource remains reachable through private endpoints, service endpoints, or via Azure Virtual Network integration. Thus, this setting is not a defect; it is a defensive measure that aligns with the principle of least access, and any connectivity impact is intended and should be managed with appropriate network rules.
- ✗
Microsoft Entra ID authentication is not configured.
Why it's wrong here
While enabling Microsoft Entra ID authentication is a desirable modern security practice, the absence of this configuration is not inherently a best-practice violation. The template may be targeting a solution that relies on SQL or storage account authentication for legacy compatibility, or it might use managed identity at the application level. Without additional context, a reviewer cannot conclude that omitting Microsoft Entra ID auth makes the deployment insecure; it is simply a gap that could be considered for hardening.
Go deeper
Related to this question
About these practice questions
This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.