AZ-500 Secure compute, storage, and databases Practice Question
You have an Azure SQL Database that stores Personally Identifiable Information (PII). You need to mask the PII columns for support staff but allow full access to managers. What should you implement?
⚠ Common exam trap
Candidates often confuse Dynamic Data Masking with Row-Level Security, thinking both restrict data access, but DDM masks columns while RLS filters rows, and only DDM with UNMASK permission provides the column-level obfuscation and selective full access described.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Dynamic Data Masking with a masking policy and grant UNMASK permission to managers
Dynamic Data Masking (DDM) obfuscates sensitive data in query results based on a masking policy, without altering the underlying data. Granting the UNMASK permission to managers allows them to see the original values, while support staff see masked data. This directly meets the requirement to mask PII columns for support staff but allow full access to managers.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Dynamic Data Masking with a masking policy and grant UNMASK permission to managers
Why this is correct
Dynamic Data Masking (DDM) operates at query time, applying a masking function to the target column's values in the result set based on the executing user's permissions. By creating a masking policy on the PII column and granting the UNMASK permission only to managers, support staff automatically see obfuscated values (e.g., partial email or random digits) while managers see the plaintext. This directly satisfies the requirement to hide PII from certain roles without changing application queries or requiring client-side key management, making it a built-in, low-friction Azure SQL Database capability.
- ✗
Always Encrypted with separate column encryption keys for managers
Why it's wrong here
Always Encrypted is a client-side encryption technology where column data is encrypted before it is sent to the database, and the Azure SQL Database engine never sees plaintext during query processing. Issuing separate column encryption keys to managers would not enable role-based masking at the server side; instead, any client with the correct key and database access can decrypt the entire column, regardless of role. Additionally, Always Encrypted requires substantial application changes and disables common server-side operations like masking, searching, or computation on the encrypted column, so it is not designed for selective dynamic display masking.
- ✗
Azure Information Protection labels and encryption
Why it's wrong here
Azure Information Protection (AIP) is a classification and labeling solution intended for documents and emails, using labels that can apply encryption rights at the file level. It does not integrate with the Azure SQL Database query engine and cannot intercept or transform T-SQL result sets, so it cannot mask a column's values when support staff run SELECT queries. Since the PII is stored in a live table and must be restricted at query time, AIP's file-centric model does not address the requirement.
- ✗
Row-level security to restrict rows for support staff
Why it's wrong here
Row-level security (RLS) controls which rows a user can see by appending a predicate function to every query, effectively filtering the result set to authorized row subsets. The scenario requires hiding or masking a specific column (such as a social security number) from support staff, even while they remain able to read other columns and relevant rows. RLS cannot redact or obscure individual column values; it only narrows the vertical slice of data by row, so it does not meet the requirement.
Go deeper
Related to this question
About these practice questions
This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.