Courseiva

DP-203 Practice Question: Secure, monitor, and optimize data storage and data processing

You are implementing dynamic data masking on an Azure Synapse Analytics dedicated SQL pool. A table named Customers contains columns: CustomerID (int), Email (varchar), Phone (varchar), and CreditCard (varchar). You need to mask the Email and Phone columns so that users without elevated permissions see only the last four characters of the Email and Phone, while users with elevated permissions see the full values. You also need to ensure that the masking does not affect the storage size of the columns. What should you do?

⚠ Common exam trap

Candidates often confuse dynamic data masking with encryption or row-level security, which serve different purposes and do not provide partial masking without storage impact.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use the MASKED WITH (FUNCTION = 'partial(0,"****",4)') clause on the Email and Phone columns and grant UNMASK permission to elevated users.

Dynamic data masking in Azure Synapse Analytics dedicated SQL pools allows you to define masking rules at the column level using the MASKED WITH clause. The partial function can reveal the last four characters while masking the rest. This does not change the underlying storage size because masking is applied at query time. Granting UNMASK permission to privileged users allows them to see the full data, fulfilling the access requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Implement row-level security (RLS) on the Customers table to filter rows based on user permissions.

    Why it's wrong here

    Row-level security filters rows, not columns, and does not mask data within a row. It would not hide portions of the Email or Phone values; it would either show or hide entire rows. This does not satisfy the requirement to mask specific characters in columns. RLS is also unrelated to storage size.

  • ✗

    Encrypt the Email and Phone columns using Always Encrypted with deterministic encryption and grant decryption keys only to elevated users.

    Why it's wrong here

    Always Encrypted encrypts data at rest and in transit, but it is designed for client-side encryption and requires application changes. It does not provide partial masking; users without keys see ciphertext, not masked values. It also does not meet the requirement to show the last four characters to regular users, and it can affect storage size due to encryption overhead.

  • ✗

    Create a masked view that concatenates '****' with the last four characters of Email and Phone, and grant SELECT on the view to users.

    Why it's wrong here

    A masked view can restrict data exposure, but it does not use the built-in dynamic data masking feature and may not integrate with existing permission models. It also requires managing permissions on the view separately, and it does not automatically apply masking based on user permissions. Additionally, the view approach may not meet the requirement to not affect storage size, as it does not alter the underlying columns.

  • ✓

    Use the MASKED WITH (FUNCTION = 'partial(0,"****",4)') clause on the Email and Phone columns and grant UNMASK permission to elevated users.

    Why this is correct

    Dynamic data masking with the partial function allows you to mask a portion of the data while revealing the last four characters. The MASKED WITH clause is applied at the column level without changing storage size. Granting UNMASK permission to elevated users allows them to see the full data. This meets all requirements: masking for regular users, full access for privileged users, and no storage impact.

Go deeper

Related to this question

About these practice questions

One of 509 original DP-203 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This DP-203 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-203 exam.