DP-203 Practice Question: Secure, monitor, and optimize data storage and data processing
You are designing a data processing solution in Azure Synapse Analytics. The solution must ensure that sensitive columns containing personally identifiable information (PII) are masked at query time for users without explicit permissions. Which Azure Synapse Analytics feature should you use?
⚠ Common exam trap
It's easy for candidates to confuse encryption-at-rest (TDE, Always Encrypted) with query-time masking; candidates often pick Always Encrypted thinking it hides data from unauthorized users, but it actually requires the client to decrypt, so it does not mask for users without permissions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Dynamic Data Masking
Dynamic Data Masking (DDM) in Azure Synapse Analytics masks sensitive column data at query time for users without explicit UNMASK permissions, returning masked values (e.g., XXXX or 0) instead of the real data. It is applied via a MASKED WITH clause on the column definition and does not alter the stored data, making it the correct choice for query-time PII obfuscation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Row-Level Security
Why it's wrong here
Row-Level Security filters which rows a user can see, not which column values are returned, so PII columns remain fully visible within permitted rows. It is tempting because RLS restricts data by user context, which is correct when the requirement is per-user row filtering rather than masking column contents.
- ✗
Transparent Data Encryption
Why it's wrong here
Transparent Data Encryption encrypts data at rest on disk, so queries still return unmasked PII to any user with SELECT permission. It is tempting because TDE protects against stolen media, which is the right goal when compliance demands encryption of database files rather than column-level query-time masking.
- ✓
Dynamic Data Masking
Why this is correct
Dynamic Data Masking applies masking rules to designated columns so unauthorised users see obfuscated values at query time, while privileged users retain full data. This satisfies the requirement to mask PII without altering stored data.
- ✗
Always Encrypted
Why it's wrong here
Always Encrypted protects data at rest and in transit by encrypting columns client-side, with decryption keys held outside the service, so users without keys cannot read plaintext at all. It suits column-level cryptographic protection, but query-time masking for permitted users requires dynamic data masking.
Go deeper
Related to this question
Learn chapter
Implement Azure Stream Analytics
Key term
Dynamic Data Masking
Dynamic Data Masking is a security feature that automatically hides sensitive data in query results so that unauthorized users see only masked information, while authorized users see the real data.
Key term
Azure Synapse Analytics
Azure Synapse Analytics is a cloud-based data integration, warehousing, and analytics service that brings together big data and data warehouse capabilities under one platform.
About these practice questions
Courseiva writes every DP-203 question from scratch — 509 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This DP-203 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-203 exam.