Courseiva

SC-100 Practice Question: Design security solutions for applications and data

Your organization uses Microsoft Sentinel to detect threats. You need to ensure that sensitive data stored in Azure SQL Database is protected from unauthorized access by Sentinel playbooks. What should you implement?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use a managed identity assigned to the playbook to authenticate to Azure SQL

The correct option is D: use a managed identity assigned to the playbook to authenticate to Azure SQL. In Microsoft Sentinel, playbooks are Logic Apps, and when they need to access Azure SQL Database, the recommended approach is to assign a managed identity to the playbook and grant that identity the appropriate database permissions, so no credentials are stored and access is scoped to the playbook. This directly protects sensitive data by ensuring only the authorized playbook identity can authenticate to Azure SQL. Option A (dynamic data masking) limits data exposure in query results but does not control which principals can access the database. Option B (CMK for TDE) protects data at rest via encryption key management, not playbook authorization. Option C (SQL firewall rules for Sentinel IPs) is impractical because Sentinel playbooks run as Logic Apps without a fixed, reliable set of Sentinel IP addresses, and firewall rules alone do not authenticate the playbook.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable dynamic data masking on the SQL database

    Why it's wrong here

    Dynamic data masking in Azure SQL obfuscates sensitive columns in query results for non-privileged users, but it does not verify the identity of the caller or grant access rights. The playbook would still need to authenticate with credentials or a managed identity; masking merely hides data at runtime and can be bypassed by users with elevated permissions. Therefore, it is a defense-in-depth layer, not an authentication mechanism.

  • ✗

    Use customer-managed keys (CMK) for SQL Transparent Data Encryption

    Why it's wrong here

    Customer-managed keys for Transparent Data Encryption (TDE) let you control the encryption keys used to encrypt the database at rest, but encryption doesn't authenticate the playbook or authorize its queries. CMK addresses key management and compliance, not identity verification; the playbook still requires a valid login or Microsoft Entra identity to connect. Thus, CMK is irrelevant to the secure authentication problem this question targets.

  • ✗

    Configure Azure SQL firewall rules to allow only Sentinel IP addresses

    Why it's wrong here

    Azure SQL firewall rules restrict network access based on source IP addresses, but they do not validate the identity or credentials of the playbook connecting to the database. Even if only allowed IPs can reach the server, the playbook must still present a valid login or token; without authentication, the connection is rejected. Moreover, Sentinel and Logic App outbound IPs can vary, making IP-based controls a fragile substitute for identity-based authentication.

  • ✓

    Use a managed identity assigned to the playbook to authenticate to Azure SQL

    Why this is correct

    Assigning a managed identity to the playbook (a Logic App) enables it to authenticate to Azure SQL using Microsoft Entra ID tokens, eliminating hard-coded secrets. You must create a contained database user mapped to that identity (e.g., CREATE USER FROM EXTERNAL PROVIDER) and grant least-privilege permissions. This is the correct approach because it provides secure, credential-free, and automatically rotating authentication for automated workflows.

About these practice questions

This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.