AZ-500 Secure compute, storage, and databases Practice Question
You have an Azure SQL Database that contains sensitive customer data. You need to ensure that database administrators (DBAs) cannot view the data in the 'CreditCard' column. What should you implement?
⚠ Common exam trap
Candidates often confuse Dynamic Data Masking (which can be bypassed by privileged users) with Always Encrypted (which provides cryptographic separation of duties), leading them to choose masking as a simpler solution without realizing it does not protect against DBAs.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use Always Encrypted with column encryption key stored in Azure Key Vault.
Always Encrypted ensures that sensitive data, such as the 'CreditCard' column, is encrypted at rest and in transit, and that the encryption keys are never exposed to the database engine. By storing the column encryption key in Azure Key Vault, DBAs with full server access cannot decrypt the data because they lack access to the key material. This provides client-side encryption where only authorized applications with the key can view plaintext data.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable Transparent Data Encryption (TDE) on the database.
Why it's wrong here
Transparent Data Encryption (TDE) encrypts the database files, transaction logs, and backups at rest, but the encryption keys are accessible to the SQL Database service and TDE automatically decrypts data in the buffer pool when a query executes. This means any user with sufficient permissions, including DBAs, can issue SELECT queries and retrieve plaintext values. TDE protects against theft of physical storage media or backups, not against authorized yet malicious users who can query the data directly.
- ✓
Use Always Encrypted with column encryption key stored in Azure Key Vault.
Why this is correct
Always Encrypted is a client-side encryption technology where sensitive column data is encrypted in the application layer before it is ever sent to SQL Database. The column encryption key is stored in Azure Key Vault and never exposed to the database engine, so SQL Server sees only ciphertext and returns only ciphertext to the client. Even if a DBA has full server permissions, they cannot decrypt the data without the column encryption key, making it the only option here that truly prevents DBAs from viewing plaintext CreditCard data.
- ✗
Implement Azure SQL Auditing for the database.
Why it's wrong here
Azure SQL Auditing records database events, such as SELECT statements and login attempts, and writes them to an Azure Storage or Log Analytics workspace. This provides a forensic trail that can reveal who accessed sensitive data and when, but it does nothing to block or restrict that access. A DBA can still read the CreditCard numbers in plaintext; auditing only helps detect the unauthorized access after the fact, not prevent it.
- ✗
Configure Dynamic Data Masking for the 'CreditCard' column.
Why it's wrong here
Dynamic Data Masking (DDM) applies masking rules to query results so that users without the UNMASK permission see masked values like 'XXXX-XXXX-XXXX-1234'. However, DDM does not encrypt the underlying data, and users with the UNMASK permission or elevated privileges such as db_owner can query the table and see the original CreditCard numbers. A DBA with control over the database can easily issue a SELECT that bypasses masking, so DDM is inadequate for protecting data from DBAs.
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.