Courseiva

AZ-500 Secure compute, storage, and databases Practice Question

Your company uses Azure SQL Database to store customer data. You need to ensure that database administrators cannot access sensitive columns (e.g., credit card numbers) even during maintenance. What should you implement?

⚠ Common exam trap

Many exam-takers confuse Dynamic Data Masking with Always Encrypted, thinking masking prevents DBA access, but masking is easily bypassed by privileged users, whereas Always Encrypted provides cryptographic separation of duties.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Always Encrypted

Always Encrypted ensures that sensitive columns like credit card numbers are encrypted at all times — both at rest and in transit — and that the encryption keys are never revealed to the database engine. This means database administrators (DBAs) cannot decrypt the data even during maintenance, because the decryption happens only on the client side. This directly meets the requirement to prevent DBA access to sensitive columns.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Transparent Data Encryption

    Why it's wrong here

    Transparent Data Encryption (TDE) performs real-time encryption/decryption of database files, backups, and transaction logs, but it is transparent to the SQL Server Database Engine. Because the server holds the encryption key and automatically decrypts data on disk when legitimate connections query it, an administrator with elevated privileges such as db_owner or sysadmin can still see plaintext customer data. TDE protects only at rest against physical theft of media, not against malicious DBAs inside the database.

  • ✗

    Dynamic Data Masking

    Why it's wrong here

    Dynamic Data Masking provides a layer of obfuscation that modifies the query result for non-privileged users according to a masking function, but the actual column values are stored in plaintext in the data file. Any user with the UNMASK permission — typically granted to database owners or members of the db_owner fixed role — can issue a simple SELECT and see the original data. Because it is purely a display-level control and can be circumvented by inference or by elevated roles, DDM does not prevent a DBA from reading sensitive customer data.

  • ✗

    Row-level security

    Why it's wrong here

    Row-level security uses a security predicate implemented as a user-defined table function and applies it to filter which rows a query can access. It is designed to restrict rows, not columns, so if a DBA or any user has permission to query the table, they can still read every column in rows that pass the predicate. A high-privileged DBA can also alter or drop the predicate or take ownership, so RLS does not provide a reliable barrier against database administrators accessing customer data.

  • ✓

    Always Encrypted

    Why this is correct

    Always Encrypted protects sensitive columns by encrypting data in the client-side driver before it is transmitted to SQL Server, so the database engine only receives and stores ciphertext. The cryptographic keys are held outside the server—in the application’s keystore or Azure Key Vault—and are never provided to the database engine. As a result, not even a DBA with sysadmin privileges can decrypt or view the plaintext values when querying the column, since the server lacks the key material. This is the only option among these that enforces client-side encryption to defeat elevated database permissions.

About these practice questions

One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.