nerdexam
Microsoft

AZ-500 · Question #632

You have an Azure subscription. You plan to deploy an Azure SQL managed instance named AzSQL1. You need to recommend an encryption solution for AzSQL1. The solution must meet the following…

The correct answer is A. Transparent Data Encryption (TDE) with Microsoft-managed keys. All environments of Microsoft Dataverse use SQL Server Transparent Data Encryption (TDE) to perform real-time encryption of data when written to disk, also known as encryption at rest. By default, Microsoft stores and manages the database encryption key for your environments so…

Submitted by zhang_li· Mar 6, 2026Secure compute, storage, and databases

Question

You have an Azure subscription. You plan to deploy an Azure SQL managed instance named AzSQL1. You need to recommend an encryption solution for AzSQL1. The solution must meet the following requirements: - The database engine must be prevented from performing key provisioning, data encryption, and decryption operations. - Database administrators must be prevented from viewing the encrypted data in plain text. What should you include in the recommendation?

Options

  • ATransparent Data Encryption (TDE) with Microsoft-managed keys
  • BTLS
  • CAzure Disk Encryption
  • DAlways Encrypted
  • ETransparent Data Encryption (TDE) with customer-managed keys

How the community answered

(48 responses)
  • A
    75% (36)
  • B
    8% (4)
  • C
    2% (1)
  • D
    13% (6)
  • E
    2% (1)

Explanation

All environments of Microsoft Dataverse use SQL Server Transparent Data Encryption (TDE) to perform real-time encryption of data when written to disk, also known as encryption at rest. By default, Microsoft stores and manages the database encryption key for your environments so you https://learn.microsoft.com/en-us/power-platform/admin/manage-encryption-key

Topics

#Always Encrypted#SQL encryption#TDE#database administrator separation

Community Discussion

No community discussion yet for this question.

Full AZ-500 Practice