TechNuggets Academy

Secure storage, databases, and networking

Free Microsoft Certified: Azure Security Engineer Associate practice — 6 questions on Secure storage, databases, and networking, with explanations. No sign-up. Full 12-question mixed test →

Question 1 of 6 · Secure storage, databases, and networking
A financial services company stores highly sensitive SSN values in an Azure SQL Database column. Neither application developers nor DBAs with database access should ever see the plaintext values, but the application must still perform LIKE pattern-matching and range comparisons directly against the encrypted column without decrypting data on the client first. Which solution BEST meets these requirements?
Secure enclaves allow rich operations such as pattern matching and range comparisons to be performed server-side inside a hardware-protected enclave, while the data remains encrypted and unreadable to DBAs or anyone without enclave access — plaintext never leaves the enclave.
Question 2 of 6 · Secure storage, databases, and networking
Your organization needs to inspect outbound HTTPS traffic leaving a virtual network to detect and block exploit attempts against known CVEs, including decrypting and inspecting the TLS payload for malicious content. The solution must integrate with the existing Azure Firewall deployment. Which feature should you enable?
Azure Firewall Premium supports TLS inspection (decrypt, inspect, re-encrypt) combined with IDPS (Intrusion Detection and Prevention System) which can be set to Alert and Deny mode to actively block traffic matching known exploit and CVE signatures.
Question 3 of 6 · Secure storage, databases, and networking
A company hosts 200 public IP addresses across several virtual networks, but only 5 of those IPs host mission-critical services requiring volumetric DDoS mitigation, cost protection, and mitigation reporting. Enabling full protection on all 200 IPs is cost-prohibitive. Which DDoS protection approach should you implement?
DDoS IP Protection is a pay-per-protected-IP tier introduced to let customers apply advanced DDoS mitigation, cost protection, and telemetry to specific individual public IPs, which is far more cost-effective than protecting an entire virtual network when only a handful of IPs are critical.
Question 4 of 6 · Secure storage, databases, and networking
You create a private endpoint for the blob service of an Azure Storage account inside a hub virtual network. On-premises clients connect over ExpressRoute and use their own on-premises DNS servers rather than Azure DNS. Name resolution for the storage account FQDN from these on-premises clients must return the private endpoint's private IP address. What should you configure?
On-premises DNS servers cannot query an Azure Private DNS zone directly. Deploying an Azure DNS Private Resolver and configuring conditional forwarding from on-prem DNS to it allows on-premises clients to correctly resolve the privatelink zone and receive the private endpoint's IP.
Question 5 of 6 · Secure storage, databases, and networking
You must configure customer-managed keys (CMK) for encryption at rest on an Azure Storage account, using a key stored in Azure Key Vault. Which combination of configurations is REQUIRED before the storage account can successfully use the CMK?
CMK requires the storage account's managed identity to authenticate to Key Vault with wrapKey/unwrapKey/get permissions, and Azure enforces that the Key Vault has soft-delete and purge protection enabled as a mandatory prerequisite to prevent accidental key loss that would make encrypted data unrecoverable.
Question 6 of 6 · Secure storage, databases, and networking
An Application Gateway WAF_v2 deployment protecting a public web app is generating frequent false-positive blocks from the OWASP Core Rule Set (CRS) against one legitimate query string parameter. Separately, you must block any single client IP address that exceeds 100 requests per minute. Which combination of WAF configuration changes addresses BOTH requirements?
WAF supports managed rule exclusions to exempt specific request fields (like a named query string parameter) from CRS evaluation, eliminating the false positive without weakening overall protection, and custom rate-limiting rules can threshold requests per client IP per time window — directly satisfying both stated requirements.
Ready for the real thing?

The full course has two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed answer explanations.

Start my full course on Udemy →