DP-203 Develop data processing Practice Question
You need to process a large dataset that contains personally identifiable information (PII). The data must be anonymized before being used for analytics. Which Azure service should you use to apply column-level masking dynamically?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Azure Synapse Analytics dynamic data masking
Azure Synapse Analytics provides dynamic data masking at the column level. Azure Purview is for data governance. Azure API Management is for APIs. Azure Data Lake Storage does not provide masking.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Azure API Management policies
Why it's wrong here
API Management policies transform and route HTTP traffic at the API gateway, not columns within stored datasets, so they cannot apply dynamic masking to PII fields. They are tempting because they enforce data-shaping rules at the service boundary, which suits REST API mediation rather than analytics-layer anonymisation.
- ✓
Azure Synapse Analytics dynamic data masking
Why this is correct
Dynamic data masking in Azure Synapse Analytics applies masking rules at query time on designated columns, so PII stays intact at rest while unauthorised users see obfuscated values. This satisfies the requirement to anonymise PII dynamically for analytics without altering the underlying stored data.
- ✗
Azure Data Lake Storage access control lists (ACLs)
Why it's wrong here
ACLs govern which principals may read files or directories in Data Lake Storage; they do not alter column values, so PII remains visible to anyone granted access. They are tempting because they restrict data at the storage layer, which suits coarse-grained authorisation rather than dynamic column-level masking.
- ✗
Azure Purview classification and labeling
Why it's wrong here
Purview classifies and labels sensitive data for governance and discovery, but it does not rewrite or mask column values during query execution. It is tempting because it identifies PII automatically, which suits cataloguing and compliance reporting rather than dynamic column-level masking in an analytics engine.
Go deeper
Related to this question
Learn chapter
Implement Azure Stream Analytics
Key term
Dynamic Data Masking
Dynamic Data Masking is a security feature that automatically hides sensitive data in query results so that unauthorized users see only masked information, while authorized users see the real data.
Key term
Azure Synapse Analytics
Azure Synapse Analytics is a cloud-based data integration, warehousing, and analytics service that brings together big data and data warehouse capabilities under one platform.
About these practice questions
This DP-203 question is part of Courseiva's 509-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DP-203 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-203 exam.