Courseiva

SC-100 Design security solutions for infrastructure Practice Question

You need to ensure that Azure SQL Database always encrypts data at rest and in transit. Which features should you enable?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Transparent Data Encryption (TDE) and enforce TLS connections

Transparent Data Encryption (TDE) and enforce TLS connections. TDE provides encryption of data at rest by encrypting the database, backups, and transaction logs at the page level, while enforcing TLS (Transport Layer Security) ensures data in transit is encrypted between the client and Azure SQL Database. Firewall rules, Microsoft Entra ID authentication, Always Encrypted, Azure Defender, and vulnerability assessment address access control, client-side encryption, or threat detection, but they do not by themselves guarantee encryption of data at rest and in transit. Therefore, options A, C, and D do not satisfy the stated requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Firewall rules and Microsoft Entra ID authentication

    Why it's wrong here

    Firewall rules restrict network origin and Microsoft Entra ID authentication verifies identity; neither encrypts stored data or the wire protocol. Both are correct when the requirement is controlling who may connect, not guaranteeing encryption at rest and in transit.

  • ✓

    Transparent Data Encryption (TDE) and enforce TLS connections

    Why this is correct

    Transparent Data Encryption encrypts Azure SQL data at rest at the page level, while enforcing TLS connections protects data in transit. Together they satisfy the requirement to always encrypt data both at rest and in transit.

  • ✗

    Always Encrypted and firewall rules

    Why it's wrong here

    Always Encrypted protects column data at rest and in client-server transit, but firewall rules only filter source IP addresses and add no transport encryption. Firewall rules belong in a network-perimeter scenario, not one demanding encryption in transit, which needs TLS enforcement.

  • ✗

    Azure Defender for SQL and vulnerability assessment

    Why it's wrong here

    Azure Defender for SQL and vulnerability assessment detect threats and misconfigurations; they do not encrypt data at rest or in transit. They are the right selection when the requirement is continuous security monitoring and assessment of database weaknesses rather than encryption guarantees.

About these practice questions

This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.