AZ-500 exam dumps

AZ-500 practice question 175 of 273

Microsoft Azure Security Technologies. Associate level, Microsoft. Free question with the correct answer and a full explanation.

AZ-500 Question 175

Select 2

Your organization has an Azure SQL Database that needs to capture all read, write, and delete activity for audit purposes. The compliance team also requires that audit logs be retained for 180 days and remain tamper-proof. Which two configurations should you implement to meet these requirements?

  1. A

    Enable database-level auditing and direct audit logs to an Azure Storage account configured with a 180-day retention policy.

  2. B

    Enable Vulnerability Assessment in Azure SQL Database and set up daily scans for compliance reporting.

  3. C

    Configure the storage account to use immutable storage features, such as a time-based retention policy or policy-based append blobs, to prevent logs from being altered.

  4. D

    Configure Transparent Data Encryption (TDE) to encrypt the database and ensure logs are retained for 180 days.

Show answer and explanation

Correct answers: A, C

Explanation

Azure SQL Database auditing can be enabled at the server or database level to capture all relevant operations. Directing audit logs to an Azure Storage account with a configured retention period and immutability helps meet both the compliance mandates for long-term retention (180 days) and tamper-proof storage. For more details, consult Microsoft's documentation on 'Auditing for Azure SQL Database and Azure Synapse Analytics' and 'Immutable storage for Azure Blobs.'

  • A. Correct.

    Enabling database-level auditing to an Azure Storage account is a fundamental step to capture read, write, and delete operations. You must specify the retention period (180 days) in the auditing settings to meet compliance requirements.

  • B. Incorrect.

    Vulnerability Assessment focuses on scanning and reporting security vulnerabilities, not on continuously auditing or storing activity logs. It’s an important feature, but it does not fulfill the activity auditing requirements.

  • C. Correct.

    Immutable storage ensures audit logs cannot be modified once written, addressing the tamper-proof requirement. Configuring a time-based retention policy or append blobs in the storage account helps prevent alterations to the logs.

  • D. Incorrect.

    Transparent Data Encryption (TDE) encrypts data at rest, protecting against unauthorized access to the underlying storage. However, it does not create or store audit logs for read/write/delete operations.

Timed practice exam

Take a AZ-500 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam