Courseiva

DP-203 Practice Question: Secure, monitor, and optimize data storage and data processing

You need to ensure that sensitive data stored in Azure SQL Database is encrypted at rest. Which feature should you enable?

⚠ Common exam trap

Candidates often confuse Always Encrypted with TDE; Always Encrypted is for column-level encryption and requires app changes, while TDE is for entire database at rest.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Transparent Data Encryption (TDE)

Transparent Data Encryption (TDE) should be enabled to ensure sensitive data stored in Azure SQL Database is encrypted at rest. TDE encrypts the database, backups, and log files at rest without requiring changes to the application.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Always Encrypted

    Why it's wrong here

    Always Encrypted protects data in use and in transit between client and database by encrypting specific columns; data at rest in Azure SQL is already encrypted by Transparent Data Encryption. Always Encrypted is tempting because it is the strongest column-level control, but it does not address the at-rest requirement.

  • ✗

    Azure Information Protection

    Why it's wrong here

    Azure Information Protection classifies and labels documents and emails, applying encryption through Azure Rights Management; it does not encrypt Azure SQL Database storage. It is tempting because it does protect data confidentiality, but its scope is files and messages, making it the right choice for labelling sensitive Office content, not for transparent database encryption at rest.

  • ✗

    Dynamic Data Masking

    Why it's wrong here

    Dynamic Data Masking only obscures column values in query results for non-privileged users; the underlying data remains unencrypted on disk. It suits limiting exposure of sensitive values in application queries, not satisfying an encryption-at-rest requirement.

  • ✓

    Transparent Data Encryption (TDE)

    Why this is correct

    Transparent Data Encryption performs real-time encryption and decryption of the database, associated backups, and transaction log files at rest without application changes. It satisfies the requirement by encrypting Azure SQL Database storage using an AES-256 symmetric key protected by a service-managed or customer-managed certificate in Microsoft Entra ID-backed key vaults.

About these practice questions

One of 509 original DP-203 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This DP-203 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-203 exam.