SC-100 Practice Question: Design security solutions for applications and data
Your organization uses Microsoft Sentinel to detect threats. You need to ensure that sensitive data stored in Azure SQL Database is protected from unauthorized access by Sentinel playbooks. What should you implement?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use a managed identity assigned to the playbook to authenticate to Azure SQL
The correct option is D: use a managed identity assigned to the playbook to authenticate to Azure SQL. In Microsoft Sentinel, playbooks are Logic Apps, and when they need to access Azure SQL Database, the recommended approach is to assign a managed identity to the playbook and grant that identity the appropriate database permissions, so no credentials are stored and access is scoped to the playbook. This directly protects sensitive data by ensuring only the authorized playbook identity can authenticate to Azure SQL. Option A (dynamic data masking) limits data exposure in query results but does not control which principals can access the database. Option B (CMK for TDE) protects data at rest via encryption key management, not playbook authorization. Option C (SQL firewall rules for Sentinel IPs) is impractical because Sentinel playbooks run as Logic Apps without a fixed, reliable set of Sentinel IP addresses, and firewall rules alone do not authenticate the playbook.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable dynamic data masking on the SQL database
Why it's wrong here
Dynamic data masking in Azure SQL obfuscates sensitive columns in query results for non-privileged users, but it does not verify the identity of the caller or grant access rights. The playbook would still need to authenticate with credentials or a managed identity; masking merely hides data at runtime and can be bypassed by users with elevated permissions. Therefore, it is a defense-in-depth layer, not an authentication mechanism.
- ✗
Use customer-managed keys (CMK) for SQL Transparent Data Encryption
Why it's wrong here
Customer-managed keys for Transparent Data Encryption (TDE) let you control the encryption keys used to encrypt the database at rest, but encryption doesn't authenticate the playbook or authorize its queries. CMK addresses key management and compliance, not identity verification; the playbook still requires a valid login or Microsoft Entra identity to connect. Thus, CMK is irrelevant to the secure authentication problem this question targets.
- ✗
Configure Azure SQL firewall rules to allow only Sentinel IP addresses
Why it's wrong here
Azure SQL firewall rules restrict network access based on source IP addresses, but they do not validate the identity or credentials of the playbook connecting to the database. Even if only allowed IPs can reach the server, the playbook must still present a valid login or token; without authentication, the connection is rejected. Moreover, Sentinel and Logic App outbound IPs can vary, making IP-based controls a fragile substitute for identity-based authentication.
- ✓
Use a managed identity assigned to the playbook to authenticate to Azure SQL
Why this is correct
Assigning a managed identity to the playbook (a Logic App) enables it to authenticate to Azure SQL using Microsoft Entra ID tokens, eliminating hard-coded secrets. You must create a contained database user mapped to that identity (e.g., CREATE USER FROM EXTERNAL PROVIDER) and grant least-privilege permissions. This is the correct approach because it provides secure, credential-free, and automatically rotating authentication for automated workflows.
Go deeper
Related to this question
About these practice questions
This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.