AZ-500 exam dumps

AZ-500 practice question 170 of 273

Microsoft Azure Security Technologies. Associate level, Microsoft. Free question with the correct answer and a full explanation.

AZ-500 Question 170

Select 2

You are planning the security configuration for a newly provisioned Azure SQL Managed Instance that stores highly confidential financial data. The organization requires that data be encrypted both at rest and in transit, and that only Azure Active Directory identities be allowed to connect. They also want to minimize public exposure of the Managed Instance. Which configurations should you implement?

  1. A

    Enable Transparent Data Encryption using a customer-managed key for at-rest data encryption

  2. B

    Disable TLS/SSL connections to improve performance

  3. C

    Create and allow client IPs in the server-level firewall rules for public access

  4. D

    Configure a private endpoint or Virtual Network to restrict inbound connections

  5. E

    Use only SQL authentication with complex passwords

Show answer and explanation

Correct answers: A, D

Explanation

Azure SQL Managed Instance security involves a multi-layered approach. To protect data at rest, use TDE; for more granular control, configure customer-managed keys in Azure Key Vault. For in-transit encryption, maintain TLS/SSL. To ensure minimal public exposure, deploy Managed Instances with private endpoints or within a Virtual Network. Finally, Azure AD authentication is recommended for modern identity management, offering centralized control and reduced credential management overhead. For more details, see Microsoft Docs: https://learn.microsoft.com/azure/azure-sql/managed-instance/security-overview.

  • A. Correct.

    Correct. Transparent Data Encryption (TDE) with a customer-managed key ensures your data is encrypted at rest. By default, Azure provides TDE, but using a customer-managed key (CMK) can offer greater control over key management

  • B. Incorrect.

    Incorrect. Disabling TLS/SSL would leave data in transit unprotected, contradicting the requirement to secure data during transmission

  • C. Incorrect.

    Incorrect. While server-level firewall rules can allow specific IP addresses, they do not minimize public exposure as effectively as private endpoints or Virtual Network integration

  • D. Correct.

    Correct. Configuring a private endpoint or using a Virtual Network restricts traffic to trusted networks only. This significantly reduces the attack surface by preventing direct public access

  • E. Incorrect.

    Incorrect. Enforcing Azure Active Directory (Azure AD) authentication is a best practice to meet modern security and compliance requirements. Reliance on only SQL authentication does not satisfy the requirement to use Azure AD identities

Timed practice exam

Take a AZ-500 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam