Courseiva

DP-203 Practice Question: Secure, monitor, and optimize data storage and data processing

Your organization has an Azure Synapse Analytics dedicated SQL pool that stores sensitive customer data. You need to ensure that only authorized users can access the data, and auditing must be enabled to track all access attempts. What should you do first?

⚠ Common exam trap

DP-203 often tests the ordering of security controls, catching candidates who jump to masking or auditing before establishing authentication and RBAC as the foundational layer.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure Microsoft Entra ID authentication and use RBAC to grant only necessary permissions.

Before implementing column-level security, dynamic data masking, or auditing, you must first establish who the authorized users are by configuring Microsoft Entra ID authentication and applying RBAC to grant only the necessary permissions. This foundational identity and access control step ensures that subsequent security features (masking, column-level security, auditing) operate against a properly authenticated and authorized user base.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Implement column-level security to restrict sensitive columns.

    Why it's wrong here

    Column-level security restricts which columns a user may read, but it neither grants access to the pool nor records access attempts. Auditing requires configuring Microsoft Entra ID authentication and enabling auditing at the workspace or server level first. Column-level security suits scenarios where users need row access but must be denied specific sensitive fields.

  • ✗

    Enable auditing on the SQL pool and configure a storage account for audit logs.

    Why it's wrong here

    Auditing records access attempts but does not restrict who can reach the data; authorisation is enforced separately through database roles, permissions, or row-level security. Enabling auditing first addresses only the tracking requirement. It is the right step once access controls are defined, not before.

  • ✓

    Configure Microsoft Entra ID authentication and use RBAC to grant only necessary permissions.

    Why this is correct

    Microsoft Entra ID authentication with RBAC establishes identity-based access control before any data-level permissions are granted, ensuring only authorised users reach the dedicated SQL pool. This is the prerequisite step, since auditing and finer controls depend on that authentication foundation being configured first.

  • ✗

    Apply dynamic data masking to the sensitive columns.

    Why it's wrong here

    Dynamic data masking obscures column values in query results but does not prevent access to the underlying data or log access attempts, so it satisfies neither requirement. It suits limiting exposure of sensitive values to non-privileged users. Authorisation and auditing must be configured first.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

Go deeper

Related to this question

About these practice questions

One of 509 original DP-203 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This DP-203 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-203 exam.