nerdexam
Microsoft

AZ-500 · Question #386

You have an Azure subscription that contains an Azure SQL database named SQL1 and an Azure key vault named KeyVault1. KeyVault1 stores the keys shown in the following table. You reed to configure…

The correct answer is D. Key1 and key2 only. The key must be an asymmetric, RSA or RSA HSM key. The supported key lengths are 2048-bit https://docs.microsoft.com/en-us/azure/azure-sql/database/transparent-data-encryption-byok-

Submitted by suresh_in· Mar 6, 2026Secure compute, storage, and databases

Question

You have an Azure subscription that contains an Azure SQL database named SQL1 and an Azure key vault named KeyVault1. KeyVault1 stores the keys shown in the following table. You reed to configure Transparent Data Encryption (TDE). TDE will use a customer-managed key for SQL1?

Exhibits

AZ-500 question #386 exhibit 1
AZ-500 question #386 exhibit 2

Options

  • AKey1, Key2, Key3 and Key4
  • BKey1 only
  • CKey2 only
  • DKey1 and key2 only
  • EKey2 and Key3 only

How the community answered

(27 responses)
  • A
    15% (4)
  • B
    7% (2)
  • D
    74% (20)
  • E
    4% (1)

Explanation

The key must be an asymmetric, RSA or RSA HSM key. The supported key lengths are 2048-bit https://docs.microsoft.com/en-us/azure/azure-sql/database/transparent-data-encryption-byok-

Community Discussion

No community discussion yet for this question.

Full AZ-500 Practice