AZ-500 Secure compute, storage, and databases Practice Question
An Azure SQL Database contains salary data. Support analysts need to query employee records but must not see full salary values. Which feature is most appropriate when the application cannot be changed immediately?
⚠ Common exam trap
Many exam-takers confuse data-at-rest encryption (TDE) with data-masking at query time—candidates often assume encryption alone prevents unauthorized viewing, but encryption does not affect what authorized users see when they run SELECT queries.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Dynamic data masking
Dynamic data masking (DDM) is the correct choice because it obfuscates sensitive data in query results without modifying the underlying database or requiring application changes. The support analysts can still query employee records, but the salary column is masked according to a defined masking rule (e.g., showing only the last four digits or replacing with zeros). This meets the requirement of preventing full salary exposure while the application remains unchanged.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Transparent Data Encryption
Why it's wrong here
Transparent Data Encryption (TDE) encrypts the underlying data and transaction log files at rest, providing protection against theft or compromise of the physical storage. However, TDE does not intercept or alter query results—when an analyst executes a SELECT, the database engine transparently decrypts the data and returns the real salary value. Since the requirement is to prevent support analysts from seeing sensitive salary information during normal query access, TDE fails to address that need and is therefore incorrect.
- ✓
Dynamic data masking
Why this is correct
Dynamic Data Masking (DDM) is a column-level, query-time control that applies masking rules to results returned to non-privileged users, making salary values appear as partial, default, or random placeholders. Because the masking is applied dynamically without modifying the underlying data, analysts can still query the table and see non-sensitive columns while sensitive salary content is obscured. This precisely satisfies the need to let support analysts work with the database without exposing salary data.
- ✗
Geo-replication
Why it's wrong here
Geo-replication creates a continuously updated readable secondary database in a different Azure region, primarily for disaster recovery and to offload read-only workloads. It replicates all schema and data—including salary values—without any filtering or scrambling, so an analyst with access to the secondary would see the identical unmasked data. It provides no mechanism for hiding sensitive columns from specific users, so it cannot meet the stated requirement.
- ✗
Accelerated database recovery
Why it's wrong here
Accelerated Database Recovery (ADR) is a recovery mechanism that uses row-level versioning and a persistent version store to eliminate the need for a traditional, potentially lengthy undo log after a transaction rollback or process restart. It improves database availability and recovery time objectives but has absolutely no effect on query results, permissions, or data visibility. Since it neither masks nor restricts salary data from analysts, it is unrelated to the requirement.
Go deeper
Related to this question
About these practice questions
This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.