Courseiva

SC-100 Transparent Data Encryption (TDE) Practice Question

You are designing a security solution for an Azure SQL Database that stores sensitive customer data. The solution must encrypt the database at rest and in transit, and also mask sensitive columns from non-privileged users. Which combination of features should you implement?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Transparent Data Encryption (TDE) and Dynamic Data Masking (DDM)

Option A is correct because Transparent Data Encryption (TDE) provides encryption at rest for Azure SQL Database by encrypting the database files, and Dynamic Data Masking (DDM) masks sensitive columns from non-privileged users by obfuscating data in query results without changing the stored data. Azure SQL Database also enforces encryption in transit by default via TLS, so TDE plus DDM satisfies the stated requirements. Option B is wrong because Always Encrypted protects data at rest and in use at the client, but it does not by itself mask columns from non-privileged users, and Row-Level Security restricts rows rather than masking columns. Option C is wrong because Always Encrypted does not provide column masking for non-privileged users. Option D is wrong because cell-level encryption and row-level security address encryption and row filtering, not the required column masking.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Transparent Data Encryption (TDE) and Dynamic Data Masking (DDM)

    Why this is correct

    TDE encrypts the entire Azure SQL database, including backups and transaction logs, transparently to applications, satisfying the at-rest encryption requirement without schema changes. DDM complements this by obfuscating sensitive columns at query runtime for non-privileged users, preventing accidental exposure of sensitive data over the network or in application results. Together they provide encryption at rest plus a display-level control, covering both storage and query-time confidentiality.

  • ✗

    Always Encrypted and Row-Level Security

    Why it's wrong here

    Always Encrypted protects individual columns using client-side encryption, with the database engine never seeing plaintext, but it does not encrypt the entire database at rest, so backups, transaction logs, and non-encrypted columns remain exposed. Row-Level Security (RLS) filters rows based on user predicates and acts as a row-level access control, but it does not encrypt anything. This combination would fail the stated requirement for full at-rest database encryption, which only TDE can satisfy.

  • ✗

    Always Encrypted and Dynamic Data Masking (DDM)

    Why it's wrong here

    Always Encrypted encrypts specific columns but not the whole database at rest, so it cannot replace TDE for the at-rest requirement. Dynamic Data Masking (DDM) obfuscates data at query time, yet when Always Encrypted is used, the server only sees ciphertext and DDM may not even be able to mask the decrypted values on the client side. More importantly, neither component encrypts the underlying database files, backups, or logs, so the solution does not meet the encryption-at-rest mandate.

  • ✗

    Cell-level encryption and row-level security

    Why it's wrong here

    Cell-level encryption is not a built-in feature in Azure SQL Database; any per-cell encryption requires custom application logic or third-party libraries, making it an unreliable and non-transparent choice for a managed service. Row-Level Security (RLS) enforces row-level access control via security predicates but does not encrypt data at rest. This combination lacks native database-level encryption, leaving database files, backups, and logs vulnerable, so it cannot satisfy the stated security design.

About these practice questions

This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.