exam questions

Exam AZ-305 All Questions

View all questions & answers for the AZ-305 exam

Exam AZ-305 topic 2 question 19 discussion

Actual exam question from Microsoft's AZ-305
Question #: 19
Topic #: 2
[All AZ-305 Questions]

You have an app named App1 that uses an on-premises Microsoft SQL Server database named DB1.

You plan to migrate DB1 to an Azure SQL managed instance.

You need to enable customer managed Transparent Data Encryption (TDE) for the instance. The solution must maximize encryption strength.

Which type of encryption algorithm and key length should you use for the TDE protector?

  • A. RSA 3072
  • B. AES 256
  • C. RSA 4096
  • D. RSA 2048
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
NotMeAnyWay
Highly Voted 2 years, 1 month ago
Selected Answer: A
A. RSA 3072 RSA 3072 provides a higher level of encryption strength compared to RSA 2048. While RSA 4096 offers even stronger encryption, it is not supported by Azure SQL Database and Azure SQL Managed Instance for TDE protectors. By choosing RSA 3072 for the TDE protector, you ensure strong encryption for your Azure SQL Managed Instance while complying with the platform's requirements. This will help protect sensitive data and maintain compliance with relevant security standards and regulations.
upvoted 28 times
chair123
1 year, 1 month ago
Correct, Reference: https://learn.microsoft.com/en-us/azure/azure-sql/database/transparent-data-encryption-byok-overview?view=azuresql#:~:text=TDE%20protector%20can%20only%20be%20an%20asymmetric%2C%20RSA%2C%20or%20RSA%20HSM%20key.%20The%20supported%20key%20lengths%20are%202048%20bits%20and%203072%20bits.
upvoted 3 times
...
...
wdjonz
Highly Voted 1 year, 11 months ago
The Answer is A and here is why... Per https://learn.microsoft.com/en-us/azure/azure-sql/database/transparent-data-encryption-tde-overview?view=azuresql&tabs=azure-portal, if the TDE uses the system managed key, it uses a built in certificate for encryption, hence AES 256 if the TDE uses a customer managed key, then it uses an asymmetric RSA key at 2048 or 3072 And since the question says TDE is using the customer managed key... the answer is A Viola!
upvoted 9 times
...
serbanvadi
Most Recent 4 weeks, 1 day ago
Selected Answer: A
TDE protector can only be an asymmetric, RSA, or RSA HSM key. The supported key lengths are 2048 bits and 3072 bits. https://learn.microsoft.com/en-us/azure/azure-sql/database/transparent-data-encryption-byok-overview?view=azuresql#requirements-for-configuring-tde-protector
upvoted 1 times
...
KA2023
1 month, 2 weeks ago
Selected Answer: B
RSA (2048, 3072, 4096) is an asymmetric encryption algorithm used primarily for key encryption and signing, not for bulk data encryption like TDE. The correct answer is still B. AES 256
upvoted 2 times
...
[Removed]
5 months, 2 weeks ago
Selected Answer: A
A is correct
upvoted 1 times
...
GabiBT
9 months ago
Actualmente RSA 4096 ya es compatible con Azure SQL Database
upvoted 1 times
...
peterp007
1 year, 3 months ago
Was on my exam today - 4th Jan 2024
upvoted 9 times
...
babakeyfgir
1 year, 5 months ago
it was a exam Question
upvoted 6 times
...
Elecktrus
1 year, 7 months ago
Selected Answer: A
RSA 3072, because is custom managed
upvoted 2 times
...
sw1000
1 year, 11 months ago
Selected Answer: A
There are a lot of confusing elements in this question. At first it mentions on-premise SQL Server, which would allow AES or RSA ... However, the system is to be migrated over to Azure. And here the requirements for customer managed TDE are pretty clear and are listed here: https://learn.microsoft.com/en-us/azure/azure-sql/database/transparent-data-encryption-byok-overview?view=azuresql#requirements-for-configuring-tde-protector AES can be enabled as an additional Infrastructure encryption to have two layers, but that was not the question here.
upvoted 3 times
...
Tr619899
1 year, 11 months ago
https://learn.microsoft.com/en-us/azure/azure-sql/database/transparent-data-encryption-byok-overview?source=recommendations&view=azuresql#requirements-for-configuring-tde-protector A. 3072
upvoted 3 times
...
zellck
2 years, 2 months ago
Selected Answer: A
A is the answer. https://learn.microsoft.com/en-us/azure/azure-sql/database/transparent-data-encryption-byok-overview?view=azuresql#requirements-for-configuring-tde-protector TDE protector can only be an asymmetric, RSA, or RSA HSM key. The supported key lengths are 2048 bytes and 3072 bytes.
upvoted 5 times
...
dagomo
2 years, 2 months ago
Selected Answer: A
https://learn.microsoft.com/en-us/azure/azure-sql/database/transparent-data-encryption-byok-overview?view=azuresql#requirements-for-configuring-tde-protector
upvoted 4 times
...
VBK8579
2 years, 2 months ago
Selected Answer: A
Answer A because Azure SQL Database and Azure Synapse Analytics support RSA 3072-bit key length for customer managed TDE with Bring Your Own Key (BYOK) configurations
upvoted 2 times
...
bigz2021
2 years, 2 months ago
A. RSA 3072 ( TDE protector can only be an asymmetric, RSA, or RSA HSM key. The supported key lengths are 2048 bytes and 3072 bytes.)
upvoted 4 times
...
OPT_001122
2 years, 2 months ago
Selected Answer: A
A. RSA 3072
upvoted 4 times
...
OPT_001122
2 years, 2 months ago
A. RSA 3072
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago