DP-203 Practice Question: Secure, monitor, and optimize data storage and data processing
Your organization has an Azure Synapse Analytics dedicated SQL pool that stores sensitive customer data. You need to ensure that only authorized users can access the data, and auditing must be enabled to track all access attempts. What should you do first?
⚠ Common exam trap
DP-203 often tests the ordering of security controls, catching candidates who jump to masking or auditing before establishing authentication and RBAC as the foundational layer.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure Microsoft Entra ID authentication and use RBAC to grant only necessary permissions.
Before implementing column-level security, dynamic data masking, or auditing, you must first establish who the authorized users are by configuring Microsoft Entra ID authentication and applying RBAC to grant only the necessary permissions. This foundational identity and access control step ensures that subsequent security features (masking, column-level security, auditing) operate against a properly authenticated and authorized user base.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Implement column-level security to restrict sensitive columns.
Why it's wrong here
Column-level security restricts which columns a user may read, but it neither grants access to the pool nor records access attempts. Auditing requires configuring Microsoft Entra ID authentication and enabling auditing at the workspace or server level first. Column-level security suits scenarios where users need row access but must be denied specific sensitive fields.
- ✗
Enable auditing on the SQL pool and configure a storage account for audit logs.
Why it's wrong here
Auditing records access attempts but does not restrict who can reach the data; authorisation is enforced separately through database roles, permissions, or row-level security. Enabling auditing first addresses only the tracking requirement. It is the right step once access controls are defined, not before.
- ✓
Configure Microsoft Entra ID authentication and use RBAC to grant only necessary permissions.
Why this is correct
Microsoft Entra ID authentication with RBAC establishes identity-based access control before any data-level permissions are granted, ensuring only authorised users reach the dedicated SQL pool. This is the prerequisite step, since auditing and finer controls depend on that authentication foundation being configured first.
- ✗
Apply dynamic data masking to the sensitive columns.
Why it's wrong here
Dynamic data masking obscures column values in query results but does not prevent access to the underlying data or log access attempts, so it satisfies neither requirement. It suits limiting exposure of sensitive values to non-privileged users. Authorisation and auditing must be configured first.
Visual reference
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
Learn chapter
Implement Data Encryption and Access Control
Key term
Azure Synapse Analytics
Azure Synapse Analytics is a cloud-based data integration, warehousing, and analytics service that brings together big data and data warehouse capabilities under one platform.
Key term
Dynamic Data Masking
Dynamic Data Masking is a security feature that automatically hides sensitive data in query results so that unauthorized users see only masked information, while authorized users see the real data.
About these practice questions
One of 509 original DP-203 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This DP-203 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-203 exam.