exam questions

Exam AZ-500 All Questions

View all questions & answers for the AZ-500 exam

Exam AZ-500 topic 1 question 43 discussion

Actual exam question from Microsoft's AZ-500
Question #: 43
Topic #: 1
[All AZ-500 Questions]

DRAG DROP -
Your company has an Azure SQL database that has Always Encrypted enabled.
You are required to make the relevant information available to application developers to allow them to access data in the database.
Which two of the following options should be made available? Answer by dragging the correct options from the list to the answer area.
Select and Place:

Show Suggested Answer Hide Answer
Suggested Answer:
Always Encrypted uses two types of keys: column encryption keys and column master keys. A column encryption key is used to encrypt data in an encrypted column. A column master key is a key-protecting key that encrypts one or more column encryption keys.
Reference:
https://docs.microsoft.com/en-us/sql/relational-databases/security/encryption/always-encrypted-database-engine

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
zellck
Highly Voted 1 year, 11 months ago
1. column master key 2. column encryption key https://learn.microsoft.com/en-us/sql/relational-databases/security/encryption/overview-of-key-management-for-always-encrypted Always Encrypted uses two types of cryptographic keys to protect your data - one key to encrypt your data, and another key to encrypt the key that encrypts your data. The column encryption key encrypts your data, the column master key encrypts the column encryption key.
upvoted 8 times
zellck
1 year, 11 months ago
Gotten this in May 2023 exam.
upvoted 6 times
...
...
majstor86
Highly Voted 2 years, 1 month ago
Column Encryption Key Column Master Key.
upvoted 6 times
...
stonwall12
Most Recent 2 months, 2 weeks ago
Answer: 1. Column encryption key 2. Column master key Reason: 1. Column Master Key (CMK): This is the root key used to protect the column encryption keys. It's typically stored in a secure location like Azure Key Vault. Developers need access to this key to be able to decrypt the column encryption keys. 2. Column Encryption Key (CEK): This key is used to encrypt the actual data in the database columns. It's protected by the column master key. Reference: https://learn.microsoft.com/en-us/sql/relational-databases/security/encryption/overview-of-key-management-for-always-encrypted https://learn.microsoft.com/en-us/sql/relational-databases/security/encryption/overview-of-key-management-for-always-encrypted?view=sql-server-ver16
upvoted 1 times
...
Ruffyit
5 months, 4 weeks ago
1. column master key 2. column encryption key https://learn.microsoft.com/en-us/sql/relational-databases/security/encryption/overview-of-key-management-for-always-encrypted Always Encrypted uses two types of cryptographic keys to protect your data - one key to encrypt your data, and another key to encrypt the key that encrypts your data. The column encryption key encrypts your data, the column master key encrypts the column encryption key.
upvoted 1 times
...
Ivan80
1 year, 2 months ago
In exam 1/28/24
upvoted 4 times
...
MikeScout
1 year, 4 months ago
I do not think that a policy is required as it only needs 'specific permissions'. Please see the following. To access an encrypted column, your application needs to be able to access Azure Key Vault and it also needs specific permissions on the column master key to decrypt the column encryption key protecting the column. To manage keys for Always Encrypted, you need permissions to list and create column master keys in Azure Key Vault, and to perform cryptographic operations using the keys. https://learn.microsoft.com/en-us/sql/relational-databases/security/encryption/create-and-store-column-master-keys-always-encrypted?view=sql-server-ver16
upvoted 2 times
...
elster
1 year, 5 months ago
The question is which information has to be made available to the application developer. As the column master key is stored in KeyVault, shouldn't the right answer then be 'A key vault access policy' instead of 'column master key', because other than the encryption key the master key will not be handed over directly to the app developer, but the latter has to fetch it from key vault, which will work only with an appropriate key vault access policy.
upvoted 2 times
pentium75
9 months ago
Tricky, but question is "which information has to be made available to the application developer". The "key vault access policy" is NOT something that you 'make available to the developer'. The "key vault access policy" is something that you CREATE, and BY DOING SO you 'make the column master key available to the developer' (= allow him to read it from key vault).
upvoted 1 times
...
...
ESAJRR
1 year, 9 months ago
1. column master key 2. column encryption key
upvoted 5 times
...
Andre369
1 year, 11 months ago
A. The column encryption key: This key is used to encrypt and decrypt the sensitive columns in the database. Application developers will need access to this key to perform encryption and decryption operations. F. The column master key: This key is used to protect the column encryption keys. It is stored in a trusted key store, such as Azure Key Vault. Application developers will need access to this key to access and manage the column encryption keys.
upvoted 5 times
...
003nickm
2 years, 1 month ago
On 2-March-2023, I passed AZ-500 with flying colur. This question was in exam. Some question were on Defender EASM as well.
upvoted 4 times
...
Diallo18
2 years, 6 months ago
In Exam 10/18/2022. One case study, no lab.
upvoted 2 times
...
Eltooth
3 years, 1 month ago
Answer is correct.
upvoted 1 times
...
Incredible99
3 years, 4 months ago
Correct answer. In 12/18/21 exams
upvoted 4 times
...
LDodge
3 years, 4 months ago
Correct- Column Encryption Key and Column Master Key.
upvoted 4 times
...
rohitmedi
3 years, 5 months ago
correct answer
upvoted 1 times
...
ReadyToLearn
3 years, 6 months ago
Answer is correct
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago