Courseiva
Develop data processing →hardMultiple Choice

DP-203 Develop data processing Practice Question

You are designing a data processing solution for a financial services company. The solution must process sensitive customer data and comply with GDPR. The data will be stored in Azure Synapse Analytics. You need to ensure that only authorized users can view specific columns (e.g., credit card numbers). Which security feature should you implement?

⚠ Common exam trap

It's easy for candidates to confuse Dynamic data masking with access control, but masking only hides data from the UI while still allowing underlying access, whereas column-level security actually prevents unauthorized users from reading the column data at all.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Column-level security

Column-level security (CLS) in Azure Synapse Analytics allows you to restrict access to specific columns in a table, such as credit card numbers, by granting or denying SELECT permissions on those columns. This directly meets the GDPR requirement to limit exposure of sensitive personal data to authorized users only, without affecting access to other columns.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Row-level security (RLS)

    Why it's wrong here

    Row-level security filters which rows a user can retrieve, not which columns; a predicate on a customer identifier leaves the credit card column fully visible to anyone permitted the row. Column-level security grants are needed to restrict specific columns. RLS is correct when the requirement is per-tenant or per-region row isolation, such as restricting a branch to its own customers.

  • ✓

    Column-level security

    Why this is correct

    Column-level security in Azure Synapse Analytics grants SELECT permissions on individual columns, so credit card numbers stay hidden from users lacking explicit column grants. This satisfies the GDPR requirement that only authorised users view specific columns, while the rest of the table remains queryable.

  • ✗

    Dynamic data masking

    Why it's wrong here

    Dynamic data masking obscures column values in query results but does not prevent access: users with SELECT permission can still retrieve unmasked data through inference or alternate queries. The stem requires only authorised users to view credit card numbers, which demands column-level security grants. Masking suits limiting incidental exposure to non-privileged staff, not enforcing column authorisation.

  • ✗

    Microsoft Defender for Cloud

    Why it's wrong here

    Defender for Cloud supplies posture management and threat protection across Azure resources; it cannot restrict which columns a query returns. Column-level authorisation requires a data-plane control such as column-level security grants or dynamic data masking. Defender for Cloud would be the right choice for detecting misconfigurations and anomalous access attempts, not for filtering query output.

About these practice questions

Courseiva writes every DP-203 question from scratch — 509 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DP-203 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-203 exam.