Microsoft Azure Security Engineer Associate AZ-500 Practice Question
You are designing data protection for an Azure SQL Database that stores customers' credit-card numbers. Compliance rules state that the data must always remain encrypted on the server and in transit, and must be unreadable even to Azure platform administrators and database administrators during query processing. The application still needs to perform exact-match searches against the credit-card column. Which Azure SQL feature should you recommend to meet these requirements?
Configure Azure SQL Database Always Encrypted with deterministic encryption on the credit-card column.
Apply Dynamic Data Masking with a custom mask on the credit-card column.
Enable Transparent Data Encryption and store the encryption key in Azure Key Vault (customer-managed key).
Implement Row-Level Security using Azure AD group predicates for the credit-card table.
Always Encrypted encrypts sensitive columns on the client before the data is sent to Azure SQL Database and keeps them encrypted at rest, in transit, and in memory on the server. Because the encryption keys never leave the client, high-privilege roles such as DBAs or Azure administrators cannot view the plaintext. When deterministic encryption is chosen, the database engine can still perform equality comparisons, allowing exact-match searches. Transparent Data Encryption only protects data at rest and exposes plaintext to DBAs in memory; Dynamic Data Masking obfuscates query results but does not encrypt data; Row-Level Security restricts rows returned, not column encryption.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Always Encrypted in Azure SQL Database?
Open an interactive chat with Bash
How does deterministic encryption enable exact-match searches?
Open an interactive chat with Bash
What is the difference between Always Encrypted and Transparent Data Encryption?
Open an interactive chat with Bash
Microsoft Azure Security Engineer Associate AZ-500
Secure compute, storage, and databases
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .