Courseiva

SC-100 Practice Question: Design security solutions for applications and data

You are the security architect for a financial services company that stores customer PII in an Azure SQL Database. The database currently uses service-managed Transparent Data Encryption (TDE). A new regulatory requirement mandates that the company controls and rotates the encryption keys used to protect the database, and that all key operations are auditable. You need to recommend a solution that meets the requirement with the least administrative overhead. What should you recommend?

⚠ Common exam trap

The trap here is assuming Always Encrypted is required whenever a regulation mentions customer-controlled keys, when the actual control point is the TDE key hierarchy.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure TDE with a customer-managed key stored in Azure Key Vault (BYOK).

The requirement is customer control and auditability of the keys that protect data at rest in Azure SQL Database. Transparent Data Encryption with a customer-managed key in Azure Key Vault is the native Azure SQL feature that satisfies this: the customer owns the key, controls rotation and revocation, and Key Vault diagnostics provide the audit trail. Other options either protect a different data state or shift to an unsupported platform.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable Always Encrypted with secure enclaves on the sensitive columns.

    Why it's wrong here

    Always Encrypted with secure enclaves protects data in use and in transit to the client, but it does not replace TDE key management. The requirement specifically targets the encryption keys protecting the database at rest, which is the TDE layer. Always Encrypted adds column-level protection and significant application changes without addressing the stated key-control mandate.

  • ✗

    Use service-managed TDE keys and enable Azure Policy to audit key rotation.

    Why it's wrong here

    Service-managed TDE keys are rotated by Microsoft and cannot be controlled or revoked by the customer, so the requirement for customer-controlled key rotation is not met. Azure Policy auditing does not grant key ownership. This option only adds visibility, not the control the regulator demands.

  • ✓

    Configure TDE with a customer-managed key stored in Azure Key Vault (BYOK).

    Why this is correct

    Customer-managed TDE keys in Azure Key Vault give the organization full control over key lifecycle, including rotation and revocation, and Key Vault logging records every key operation for audit. This directly satisfies the regulatory requirement for controlled, auditable key management without requiring application changes or additional infrastructure.

  • ✗

    Store the database in an Azure Disk Encryption–protected VM-hosted SQL Server instance.

    Why it's wrong here

    Azure Disk Encryption protects the OS and data disks of a virtual machine, not an Azure SQL Database PaaS service. Moving to IaaS introduces major operational overhead and does not use the managed TDE key hierarchy the regulation is concerned with. It is both a scope mismatch and a downgrade in manageability.

About these practice questions

This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.