Courseiva

DP-203 Practice Question: Secure, monitor, and optimize data storage and data processing

An organization is using Azure Synapse Analytics and wants to implement column-level security to restrict access to sensitive columns. Which feature should they use?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Column-level security using GRANT

Column-level security in Azure Synapse Analytics is implemented using GRANT statements on specific columns, restricting access to sensitive columns. Option A is incorrect because dynamic data masking obfuscates data at query time but does not prevent access. Option B is incorrect because Azure Purview is a data governance service, not for access control. Option D is incorrect because row-level security filters rows, not columns.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Dynamic data masking

    Why it's wrong here

    Dynamic data masking obscures values in query results but leaves the column itself queryable and does not prevent users selecting it; column-level security grants or denies access to the column outright. Masking suits hiding sensitive values from non-privileged viewers while retaining column access.

  • ✗

    Azure Purview

    Why it's wrong here

    Azure Purview is a data governance and cataloguing service that classifies and maps sensitive data; it does not enforce query-time column restrictions in Synapse. It would be the right choice for discovering and labelling sensitive columns across estates, not for blocking their selection.

  • ✓

    Column-level security using GRANT

    Why this is correct

    Column-level security in Azure Synapse Analytics is enforced through T-SQL GRANT statements, letting you deny SELECT on specific columns while permitting access to the rest of the table. This directly satisfies the requirement to restrict sensitive columns, unlike object-level permissions or dynamic data masking, which obscures values rather than blocking access.

  • ✗

    Row-level security

    Why it's wrong here

    Row-level security filters which rows a user retrieves, leaving every column visible; the requirement is to restrict specific columns. It would be correct where users must see only their own region's or tenant's records, not where particular fields such as salary must be hidden.

Go deeper

Related to this question

About these practice questions

Courseiva writes every DP-203 question from scratch — 509 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on DP-203

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. You need to implement column-level security in Azure Synapse Analytics to restrict access to salary information. Only users with the 'HRManager' role should see salary columns. Which feature should you use?

easy
  • A.Row-level security using security predicates
  • B.Dynamic data masking
  • ✓ C.Column-level security using GRANT on columns
  • D.Azure Purview data classification

Why C: Column-level security (CLS) in Azure Synapse Analytics uses GRANT on specific columns to restrict access. Option A is incorrect because row-level security filters rows, not columns. Option B is incorrect because dynamic data masking obfuscates data but does not prevent access. Option D is incorrect because Azure Purview is a governance tool, not a security enforcement mechanism.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DP-203 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-203 exam.