Courseiva

DP-203 Practice Question: Secure, monitor, and optimize data storage and data processing

You are designing a data processing solution in Azure Synapse Analytics. The solution must ensure that sensitive columns containing personally identifiable information (PII) are masked at query time for users without explicit permissions. Which Azure Synapse Analytics feature should you use?

⚠ Common exam trap

It's easy for candidates to confuse encryption-at-rest (TDE, Always Encrypted) with query-time masking; candidates often pick Always Encrypted thinking it hides data from unauthorized users, but it actually requires the client to decrypt, so it does not mask for users without permissions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Dynamic Data Masking

Dynamic Data Masking (DDM) in Azure Synapse Analytics masks sensitive column data at query time for users without explicit UNMASK permissions, returning masked values (e.g., XXXX or 0) instead of the real data. It is applied via a MASKED WITH clause on the column definition and does not alter the stored data, making it the correct choice for query-time PII obfuscation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Row-Level Security

    Why it's wrong here

    Row-Level Security filters which rows a user can see, not which column values are returned, so PII columns remain fully visible within permitted rows. It is tempting because RLS restricts data by user context, which is correct when the requirement is per-user row filtering rather than masking column contents.

  • ✗

    Transparent Data Encryption

    Why it's wrong here

    Transparent Data Encryption encrypts data at rest on disk, so queries still return unmasked PII to any user with SELECT permission. It is tempting because TDE protects against stolen media, which is the right goal when compliance demands encryption of database files rather than column-level query-time masking.

  • ✓

    Dynamic Data Masking

    Why this is correct

    Dynamic Data Masking applies masking rules to designated columns so unauthorised users see obfuscated values at query time, while privileged users retain full data. This satisfies the requirement to mask PII without altering stored data.

  • ✗

    Always Encrypted

    Why it's wrong here

    Always Encrypted protects data at rest and in transit by encrypting columns client-side, with decryption keys held outside the service, so users without keys cannot read plaintext at all. It suits column-level cryptographic protection, but query-time masking for permitted users requires dynamic data masking.

Go deeper

Related to this question

About these practice questions

Courseiva writes every DP-203 question from scratch — 509 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This DP-203 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-203 exam.