You will migrate an on-premises SQL Server database to an Azure SQL Managed Instance and must enable customer-managed Transparent Data Encryption (TDE). To maximize encryption strength for the TDE protector, which algorithm and key length should you choose?
Choose an answer
Tap an option to check your answer.
Correct answer: RSA 3072.
Why this is the answer
RSA 3072 is the correct choice because it is the strongest algorithm and key length supported for customer-managed TDE protectors in Azure SQL Managed Instance. While RSA 4096 offers greater theoretical strength, it is not currently supported for this specific purpose in Azure SQL Managed Instance, making it an invalid option. RSA 2048 is supported but provides less encryption strength than RSA 3072. AES 256 is a symmetric encryption algorithm used for data encryption by TDE, but it is not used for the TDE protector (the key that encrypts the data encryption key). The TDE protector is an asymmetric key (RSA).
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed