SC-100 Design security solutions for infrastructure Practice Question
You need to ensure that Azure SQL Database always encrypts data at rest and in transit. Which features should you enable?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Transparent Data Encryption (TDE) and enforce TLS connections
Transparent Data Encryption (TDE) and enforce TLS connections. TDE provides encryption of data at rest by encrypting the database, backups, and transaction logs at the page level, while enforcing TLS (Transport Layer Security) ensures data in transit is encrypted between the client and Azure SQL Database. Firewall rules, Microsoft Entra ID authentication, Always Encrypted, Azure Defender, and vulnerability assessment address access control, client-side encryption, or threat detection, but they do not by themselves guarantee encryption of data at rest and in transit. Therefore, options A, C, and D do not satisfy the stated requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Firewall rules and Microsoft Entra ID authentication
Why it's wrong here
Firewall rules restrict network origin and Microsoft Entra ID authentication verifies identity; neither encrypts stored data or the wire protocol. Both are correct when the requirement is controlling who may connect, not guaranteeing encryption at rest and in transit.
- ✓
Transparent Data Encryption (TDE) and enforce TLS connections
Why this is correct
Transparent Data Encryption encrypts Azure SQL data at rest at the page level, while enforcing TLS connections protects data in transit. Together they satisfy the requirement to always encrypt data both at rest and in transit.
- ✗
Always Encrypted and firewall rules
Why it's wrong here
Always Encrypted protects column data at rest and in client-server transit, but firewall rules only filter source IP addresses and add no transport encryption. Firewall rules belong in a network-perimeter scenario, not one demanding encryption in transit, which needs TLS enforcement.
- ✗
Azure Defender for SQL and vulnerability assessment
Why it's wrong here
Azure Defender for SQL and vulnerability assessment detect threats and misconfigurations; they do not encrypt data at rest or in transit. They are the right selection when the requirement is continuous security monitoring and assessment of database weaknesses rather than encryption guarantees.
Go deeper
Related to this question
About these practice questions
This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.