DP-203 Practice Question: Secure, monitor, and optimize data storage and data processing
You are responsible for securing an Azure Synapse Analytics workspace that contains sensitive data. You need to ensure that data is encrypted at rest using a customer-managed key stored in Azure Key Vault. What should you configure?
⚠ Common exam trap
A common mix-up: candidates confuse Always Encrypted with TDE, or assuming that Azure Storage Service Encryption applies to Synapse dedicated SQL pools.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Transparent Data Encryption (TDE) with a customer-managed key.
Transparent Data Encryption (TDE) with a customer-managed key in Azure Key Vault provides encryption at rest for Azure Synapse Analytics dedicated SQL pools. This allows you to manage the encryption key, including rotation and revocation, and meets compliance requirements for customer-managed keys.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Always Encrypted with column encryption keys.
Why it's wrong here
Always Encrypted is designed to protect data in use and at rest by encrypting individual columns. It uses column encryption keys, which are not necessarily stored in Azure Key Vault and are not the same as TDE customer-managed keys. It does not encrypt the entire database at rest.
- ✓
Transparent Data Encryption (TDE) with a customer-managed key.
Why this is correct
TDE with a customer-managed key allows you to bring your own key stored in Azure Key Vault. This gives you control over the encryption key, including rotation and revocation. It satisfies the requirement to encrypt data at rest using a customer-managed key in Azure Key Vault.
- ✗
Transparent Data Encryption (TDE) with a service-managed key.
Why it's wrong here
TDE with a service-managed key encrypts data at rest, but the key is managed by Microsoft, not by you. The requirement is to use a customer-managed key stored in Azure Key Vault, so this does not meet the requirement. TDE with customer-managed key is the correct approach.
- ✗
Azure Storage Service Encryption with a customer-managed key.
Why it's wrong here
Azure Storage Service Encryption encrypts data in Azure Storage accounts, but it does not apply to Azure Synapse Analytics dedicated SQL pools. The question is about securing data in Synapse, so this is not the correct service. TDE with customer-managed key is the appropriate feature for Synapse.
Go deeper
Related to this question
About these practice questions
This DP-203 question is part of Courseiva's 509-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This DP-203 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-203 exam.