Microsoft Azure Security Engineer Associate AZ-500 Practice Question

You manage an Azure SQL logical server that hosts the production database SalesDB. Transparent Data Encryption (TDE) is enabled and currently uses the Microsoft-managed service key. Your company now requires that all databases use a customer-managed key (CMK) stored in Azure Key Vault, but downtime and full data re-encryption must be avoided. Which action should you perform to meet the requirement?

  • Import the customer-managed key into the SalesDB master database and regenerate the database encryption key.

  • Set the TDE protector for the logical server to the customer-managed key in Azure Key Vault.

  • Turn off TDE for SalesDB, then enable it again using the key from Azure Key Vault.

  • Use Azure Database Migration Service to copy SalesDB to a new database that is encrypted with the customer-managed key.

Microsoft Azure Security Engineer Associate AZ-500
Secure compute, storage, and databases
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot