Courseiva
Design and implement data storagemediumMultiple ChoiceObjective-mapped

DP-203 Encrypt sensitive data Practice Question

Your company stores sensitive customer data in Azure SQL Database. You need to encrypt the data at rest and ensure that only your application can decrypt it, even from database administrators. What should you implement?

⚠ Common exam trap

It's easy for candidates to confuse Transparent Data Encryption (TDE) with client-side encryption, assuming TDE protects against DBA access, but TDE only protects data at rest from storage theft, not from authorized database users.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Always Encrypted

Always Encrypted is correct because it ensures that sensitive data is encrypted at rest and in use, and the encryption keys are stored client-side, so only the application can decrypt the data. Database administrators (DBAs) cannot access the plaintext data because they lack the column encryption keys, even though they have full administrative access to the database.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Transparent Data Encryption (TDE)

    Why it's wrong here

    TDE encrypts data at rest but the database engine holds the keys, allowing DBAs to decrypt.

  • Dynamic Data Masking

    Why it's wrong here

    Only masks data from unauthorized users; data is still stored in plaintext.

  • Azure Storage Service Encryption

    Why it's wrong here

    This applies to Azure Storage, not SQL Database.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The DP-203 exam frequently reuses these exact scenarios with slightly different constraints.

Always EncryptedCorrect answer
Transparent Data Encryption (TDE)Wrong answer — click to see why

Why this is wrong here

TDE encrypts data at rest but the database engine holds the keys, allowing DBAs to decrypt.

Dynamic Data MaskingWrong answer — click to see why

Why this is wrong here

Only masks data from unauthorized users; data is still stored in plaintext.

Azure Storage Service EncryptionWrong answer — click to see why

Why this is wrong here

This applies to Azure Storage, not SQL Database.

Analysis generated from the official DP-203blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

This DP-203 question is part of Courseiva's 760-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DP-203 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-203 exam.