Skip to content

Implement a secure environment Questions

Practice questions for Implement a secure environment topic in Microsoft Certified: Azure Database Administrator Associate. 43 questions covering this domain.

43 questions12 easy22 medium9 hard
Q1
easy

What does transparent data encryption protect in Azure SQL?

Q2
easy

What is the main effect of dynamic data masking?

Q3
hard

A security team grants a user the SQL DB Contributor Azure RBAC role on a logical server. The user still cannot query a database with Microsoft Entra ...

Q4
easy

Which Azure SQL authentication method enables centralized identity management, conditional access, multifactor authentication, and support for managed...

Q5
medium

A support lead should see one sensitive column in clear text but other masked columns can remain masked. What permission model should you use with dyn...

Q6
medium

A multitenant application stores rows for many tenants in the same table and must ensure each tenant can read only its own rows. Which feature should ...

Q7
hard

What is the effect of removing the Microsoft Entra administrator from an Azure SQL server or managed instance?

Q8
hard

A team uses Microsoft Purview Information Protection access policies to control access to labeled sensitive columns. They create a geo-replica of the ...

Q9
medium

A database uses Microsoft Entra authentication and participates in geo-replication or a failover group. What must be configured on both the primary an...

Q10
medium

A security analyst wants audit records to show the sensitivity labels of data returned by queries. Which feature combination provides this?

Q11
medium

A compliance team wants to manage the TDE protector in Azure Key Vault and rotate keys themselves. Which statement is true for this design?

Q12
medium

Which Azure SQL feature provides cryptographic evidence of tampering for table data using a blockchain-like ledger?

Q13
hard

An organization sees that Microsoft Defender for SQL alerts include "Potential SQL injection" but wants the alert to ignore a known internal scanner t...

Q14
medium

A team needs to allow access to an Azure SQL logical server only from a specific subnet without using a private endpoint. Which feature should they us...

Q15
easy

Where are server-level firewall rules for an Azure SQL logical server stored?

Q16
easy

Which feature ensures that sensitive column values are never visible in plaintext to the SQL engine, by encrypting on the client driver?

Q17
hard

A DBA configures customer-managed TDE on an Azure SQL logical server with a key in Azure Key Vault, and uses geo-replication to a secondary in another...

Q18
easy

What does enabling a private endpoint for an Azure SQL logical server provide?

Q19
medium

An organization wants to disallow SQL authentication and require all connections to use Microsoft Entra identities on an Azure SQL logical server. Wha...

Q20
medium

A DBA must configure auditing for an Azure SQL Database. Which destinations are supported for the audit log?

Sign in to see all 43 questions

Create a free account to browse all questions — completely free during our launch phase.