Courseiva
Develop data processinghardMultiple SelectObjective-mapped

DP-203 Develop data processing Practice Question

Which TWO techniques should you use to secure sensitive data in Azure Synapse Analytics dedicated SQL pools when implementing column-level security?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Define dynamic data masking rules to obfuscate sensitive columns for unauthorized users.

Dynamic data masking obfuscates sensitive columns for unauthorized users at query time, providing column-level security without altering the underlying data. Option D is correct because column-level security in Azure Synapse dedicated SQL pools uses GRANT SELECT on specific columns to authorized users, restricting access to sensitive columns. Option B is incorrect because Transparent Data Encryption (TDE) encrypts data at rest, not at the column level. Option C is incorrect because security policies with filter predicates are used for row-level security, not column-level security. Option E is incorrect because Always Encrypted encrypts columns at the application level, which is separate from column-level security in Synapse.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Define dynamic data masking rules to obfuscate sensitive columns for unauthorized users.

    Why this is correct

    Dynamic data masking hides sensitive data from non-privileged users.

  • Enable Transparent Data Encryption (TDE) on the database.

    Why it's wrong here

    TDE encrypts the entire database at rest, not specific columns.

  • Create a security policy with filter predicates to restrict access to specific columns.

    Why it's wrong here

    Filter predicates are for row-level security, not column-level.

  • Use GRANT SELECT on specific columns to authorized users.

    Why this is correct

    Column-level security is implemented by granting permissions on individual columns.

  • Implement Always Encrypted to encrypt columns at the application level.

    Why it's wrong here

    Always Encrypted is not supported in dedicated SQL pools.

Go deeper

Related to this question

About these practice questions

Courseiva writes every DP-203 question from scratch — 760 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DP-203 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-203 exam.