Microsoft Azure Security Engineer Associate AZ-500 Practice Question
Your company has an Azure SQL Database named SalesDB. Transparent Data Encryption (TDE) is enabled with a Microsoft-managed key. The security team must manage the TDE protector themselves and rotate it in Azure Key Vault without requiring data re-encryption. You plan to switch SalesDB to customer-managed TDE. Which prerequisite must you complete before you can set the database encryption protector to a Key Vault key?
Create an Azure Key Vault access policy that lists the public IP addresses of the SQL Database service.
Disable TDE on SalesDB, then re-enable it after configuring a new protector key.
Generate a new TDE certificate in the master database and export it to a .cer file for backup.
Grant the SQL server's managed identity the Key Vault Crypto Service Encryption User role (or equivalent key permissions) on the target key.
Before you can change the encryption protector to a customer-managed key, the Azure SQL logical server's managed identity must be able to access that key in Azure Key Vault. Granting the managed identity the Key Vault Crypto Service Encryption User (or equivalent key permissions) is required; otherwise the ALTER DATABASE ENCRYPTION PROTECTOR statement that points to the Key Vault key will fail. Disabling TDE is unnecessary, granting access by IP addresses is insufficient, and creating or exporting a database certificate is not used with TDE in Azure SQL Database.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Transparent Data Encryption (TDE) in Azure SQL Database?
Open an interactive chat with Bash
What is a customer-managed key in Azure Key Vault?
Open an interactive chat with Bash
What is a managed identity in Azure?
Open an interactive chat with Bash
Microsoft Azure Security Engineer Associate AZ-500
Secure compute, storage, and databases
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .