DP-203 Design and implement data storage Practice Question
You are designing a data storage solution for a healthcare analytics platform. The solution must store patient records in Azure SQL Database and allow point-in-time restore for any time within the last 35 days. The data must be encrypted at rest using customer-managed keys (CMK) stored in Azure Key Vault. You need to configure the Azure SQL Database to meet these requirements. What should you do?
⚠ Common exam trap
Test-takers frequently confuse long-term retention with point-in-time restore retention, leading to selection of LTR when the requirement is for point-in-time restore.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable Transparent Data Encryption (TDE) with a customer-managed key in Azure Key Vault and configure the retention policy for automated backups to 35 days.
The requirement is for encryption at rest with customer-managed keys and point-in-time restore for 35 days. TDE with a customer-managed key in Azure Key Vault provides the required encryption. Configuring the backup retention policy to 35 days enables point-in-time restore within that window. Other options either use the wrong encryption method or confuse long-term retention with point-in-time restore.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable Transparent Data Encryption (TDE) with a customer-managed key in Azure Key Vault and configure long-term retention (LTR) for 35 days.
Why it's wrong here
LTR is for long-term backup retention beyond the standard point-in-time restore period, typically up to 10 years. It does not extend point-in-time restore to 35 days. Point-in-time restore retention is configured separately and can be set up to 35 days. LTR would not satisfy the point-in-time restore requirement.
- ✓
Enable Transparent Data Encryption (TDE) with a customer-managed key in Azure Key Vault and configure the retention policy for automated backups to 35 days.
Why this is correct
TDE with a customer-managed key in Azure Key Vault satisfies the encryption at rest requirement. Azure SQL Database automatically retains backups for 7 days by default, but the retention policy can be extended up to 35 days for point-in-time restore. This configuration meets both the encryption and the 35-day point-in-time restore requirements.
- ✗
Enable Transparent Data Encryption (TDE) with a service-managed key and configure the retention policy for automated backups to 35 days.
Why it's wrong here
TDE with a service-managed key encrypts data at rest, but the requirement explicitly states customer-managed keys stored in Azure Key Vault. Service-managed keys do not meet that requirement. Backup retention can still be set to 35 days, but the encryption key management is not compliant with the specified need.
- ✗
Enable Always Encrypted with a column master key stored in Azure Key Vault and configure the retention policy for automated backups to 35 days.
Why it's wrong here
Always Encrypted protects data in use and at rest, but it encrypts specific columns and does not provide full database encryption at rest. It also does not affect backup retention. The requirement is for encryption at rest of the entire database, which is better met by TDE. Backup retention is independent of encryption configuration.
Go deeper
Related to this question
About these practice questions
This DP-203 question is part of Courseiva's 509-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This DP-203 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-203 exam.