Enforce Secure Configuration of Azure SQL Database with Azure Policy
Which TWO Azure policies should you assign to enforce secure configuration of Azure SQL Database? (Select two.)
Quick Answer
The answer is to assign the Azure Policy built-in initiatives for enabling Auditing on Azure SQL Database and for configuring Firewall and virtual network settings. Auditing is correct because it captures all database events and writes them to an audit log in your Azure storage account, Log Analytics workspace, or Event Hubs, providing a fundamental security control for compliance and forensic analysis by recording who did what and when. The firewall policy is equally essential as it enforces network-level access restrictions, preventing unauthorized connections from public endpoints. On the Microsoft Cybersecurity Architect exam, this pairing tests your understanding that secure configuration requires both detective controls (auditing) and preventive controls (network isolation), with a common trap being to select only one policy or to confuse auditing with threat detection. Remember the mnemonic “Audit the Access, Lock the Network” to recall that you need both event logging and firewall rules to enforce secure configuration of Azure SQL Database with Azure Policy.
⚠ Common exam trap
Candidates often confuse SQL Server VM policies (like TDE or SQL Server-level audit settings) with Azure SQL Database policies, or they mistakenly apply storage account policies to SQL Database, which is a separate Azure service with its own security controls.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Ensure that 'Auditing' is set to 'On' for SQL Database
Option A is correct because the built-in Azure Policy 'Auditing on SQL Database should be enabled' enforces that auditing is set to 'On' for Azure SQL Database, ensuring database activity is logged for security and compliance monitoring. Option D is correct because the policy 'Firewall and virtual network settings for SQL Database should be configured' enforces that Azure SQL Database has network-level access controls (firewall rules or virtual network service endpoints/private endpoints) in place, restricting access to authorized networks only. Option B is incorrect because it targets TDE on SQL Server running on VMs (IaaS), not Azure SQL Database (PaaS), so it does not apply to this scenario. Option C is incorrect because it audits the SQL Server-level audit setting rather than enforcing a secure configuration on Azure SQL Database itself. Option E is incorrect because it concerns secure transfer for storage accounts, which is unrelated to Azure SQL Database configuration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Ensure that 'Auditing' is set to 'On' for SQL Database
Why this is correct
Enabling SQL Database auditing satisfies the secure-configuration requirement by recording all database events to a storage, Log Analytics or Event Hub destination, giving the detective evidence trail that Azure Policy's Auditing effect enforces at scale across every server and database in scope.
- ✗
Ensure that 'TDE' is enabled for SQL Server VMs
Why it's wrong here
TDE on SQL Server VMs is configured inside the guest OS via IaaS tooling, so an Azure SQL Database policy cannot enforce it. It is tempting because TDE does protect database files at rest, but the correct policies target the PaaS SQL Database service, not virtual machines.
- ✗
Audit SQL Server level audit setting
Why it's wrong here
This policy audits the server-level audit setting rather than enforcing a secure configuration, so it detects but does not prevent misconfiguration. It is tempting because auditing underpins compliance monitoring, yet the question asks for policies that enforce security controls on Azure SQL Database.
- ✓
Ensure that 'Firewall and virtual network settings' for SQL Database are configured
Why this is correct
Configuring firewall and virtual network settings satisfies the network-isolation constraint by denying public Azure service access and permitting only approved IP ranges, private endpoints or subnet delegations, so Azure Policy blocks any SQL server left reachable from the open internet.
- ✗
Ensure secure transfer to storage accounts is enabled
Why it's wrong here
Secure transfer applies to Azure Storage account endpoints, not to Azure SQL Database connections, so it cannot enforce SQL security configuration. It is tempting because both are data services with encryption settings, but the correct policies scope to SQL Database rather than storage accounts.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
About these practice questions
This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SC-100
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Your organization uses Azure SQL Database with Azure AD authentication. You need to ensure that database administrators (DBAs) can only perform management tasks from a specific Azure region and only during business hours. Which solution should you use?
hard- ✓ A.Azure AD Conditional Access policies
- B.Azure RBAC with custom roles
- C.Azure Policy with custom policy
- D.Azure SQL Database firewall rules
Why A: Azure AD Conditional Access policies are the correct solution because they can enforce both location-based (named locations/regions) and time-based (sign-in frequency, or via authentication context combined with Conditional Access) conditions on sign-ins to Azure SQL Database when Azure AD authentication is used. This directly satisfies the requirement that DBAs perform management tasks only from a specific Azure region and only during business hours. Azure RBAC with custom roles (B) only controls what actions a principal can perform, not when or from where they sign in. Azure Policy (C) governs resource configuration and compliance, not user sign-in conditions. Azure SQL Database firewall rules (D) restrict network access by IP range but cannot enforce business-hours time restrictions.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.