Courseiva

AZ-500 Secure compute, storage, and databases Practice Question

You have an Azure SQL Database that stores Personally Identifiable Information (PII). You need to mask the PII columns for support staff but allow full access to managers. What should you implement?

⚠ Common exam trap

Candidates often confuse Dynamic Data Masking with Row-Level Security, thinking both restrict data access, but DDM masks columns while RLS filters rows, and only DDM with UNMASK permission provides the column-level obfuscation and selective full access described.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Dynamic Data Masking with a masking policy and grant UNMASK permission to managers

Dynamic Data Masking (DDM) obfuscates sensitive data in query results based on a masking policy, without altering the underlying data. Granting the UNMASK permission to managers allows them to see the original values, while support staff see masked data. This directly meets the requirement to mask PII columns for support staff but allow full access to managers.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Dynamic Data Masking with a masking policy and grant UNMASK permission to managers

    Why this is correct

    Dynamic Data Masking (DDM) operates at query time, applying a masking function to the target column's values in the result set based on the executing user's permissions. By creating a masking policy on the PII column and granting the UNMASK permission only to managers, support staff automatically see obfuscated values (e.g., partial email or random digits) while managers see the plaintext. This directly satisfies the requirement to hide PII from certain roles without changing application queries or requiring client-side key management, making it a built-in, low-friction Azure SQL Database capability.

  • ✗

    Always Encrypted with separate column encryption keys for managers

    Why it's wrong here

    Always Encrypted is a client-side encryption technology where column data is encrypted before it is sent to the database, and the Azure SQL Database engine never sees plaintext during query processing. Issuing separate column encryption keys to managers would not enable role-based masking at the server side; instead, any client with the correct key and database access can decrypt the entire column, regardless of role. Additionally, Always Encrypted requires substantial application changes and disables common server-side operations like masking, searching, or computation on the encrypted column, so it is not designed for selective dynamic display masking.

  • ✗

    Azure Information Protection labels and encryption

    Why it's wrong here

    Azure Information Protection (AIP) is a classification and labeling solution intended for documents and emails, using labels that can apply encryption rights at the file level. It does not integrate with the Azure SQL Database query engine and cannot intercept or transform T-SQL result sets, so it cannot mask a column's values when support staff run SELECT queries. Since the PII is stored in a live table and must be restricted at query time, AIP's file-centric model does not address the requirement.

  • ✗

    Row-level security to restrict rows for support staff

    Why it's wrong here

    Row-level security (RLS) controls which rows a user can see by appending a predicate function to every query, effectively filtering the result set to authorized row subsets. The scenario requires hiding or masking a specific column (such as a social security number) from support staff, even while they remain able to read other columns and relevant rows. RLS cannot redact or obscure individual column values; it only narrows the vertical slice of data by row, so it does not meet the requirement.

About these practice questions

This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.