mediumMultiple Choice
DP-203 Practice Question: A company uses Azure Synapse Analytics dedicated…
A company uses Azure Synapse Analytics dedicated SQL pool. They need to ensure that only users with a specific Microsoft Entra ID group can query a particular schema. Which approach should they use?
⚠ Common exam trap
Candidates often confuse network-level controls (firewall rules) or data obfuscation techniques (masking, RLS) with access control, when the correct solution is a straightforward permission grant using T-SQL's GRANT statement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use the GRANT statement to grant SELECT on the schema to the Microsoft Entra ID group.
The GRANT statement in Azure Synapse dedicated SQL pool allows you to assign permissions directly to Microsoft Entra ID groups. By granting SELECT on the schema to the specific Microsoft Entra ID group, only members of that group can query objects within that schema, meeting the requirement precisely.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure a server-level firewall rule to block other users.
Why it's wrong here
Firewall rules filter by network origin, not by identity, so any user connecting from a permitted address could still query the schema. Firewall rules suit restricting access by IP range, whereas schema-level authorisation requires database roles or security predicates.
- ✓
Use the GRANT statement to grant SELECT on the schema to the Microsoft Entra ID group.
Why this is correct
GRANT SELECT on the schema to the Microsoft Entra ID group grants query permission to every member through group membership, which is the granular, group-scoped control the scenario requires. This restricts access to that schema without per-user grants.
- ✗
Create a row-level security policy on all tables in the schema.
Why it's wrong here
Row-level security filters rows within tables, not schema query access, so it cannot restrict who may query the schema. It is tempting because RLS does enforce per-user data visibility, and would be correct when different users must see different subsets of rows in the same table.
- ✗
Apply dynamic data masking to the schema.
Why it's wrong here
Dynamic data masking obscures column values in query results but still permits the query to run, so it cannot prevent the Microsoft Entra ID group's non-members from querying the schema. It is tempting because masking does restrict what data users see, and would be correct when sensitive columns must be hidden from certain users.
Go deeper
Related to this question
About these practice questions
One of 509 original DP-203 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DP-203 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-203 exam.