DP-203 Practice Question: Secure, monitor, and optimize data storage and data processing
Your organization uses Azure Synapse Analytics dedicated SQL pool. You need to ensure that all data at rest in the SQL pool is encrypted using a customer-managed key stored in Azure Key Vault. What should you configure?
⚠ Common exam trap
DP-203 often tests the confusion between TDE (at-rest encryption of the whole database), Always Encrypted (column-level, client-side), and Storage Service Encryption (storage account level) — candidates must match the encryption scope to the requirement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable Transparent Data Encryption (TDE) with a customer-managed key in Azure Key Vault.
Transparent Data Encryption (TDE) with a customer-managed key in Azure Key Vault encrypts the dedicated SQL pool's data at rest (data files, log files, backups) and allows the organization to control and rotate the encryption key. TDE is the native at-rest encryption mechanism for Azure Synapse dedicated SQL pools. Configuring it with a customer-managed key in Key Vault meets the requirement precisely.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Implement Always Encrypted with column encryption keys stored in Azure Key Vault.
Why it's wrong here
Always Encrypted protects individual columns in transit and at rest from the database engine, not the entire dedicated SQL pool storage; TDE with a customer-managed key in Key Vault is required. It is tempting because it also uses Key Vault keys, and would be correct for protecting sensitive columns from DBAs.
- ✗
Configure Dynamic Data Masking to obfuscate sensitive data.
Why it's wrong here
Dynamic Data Masking hides column values in query results at runtime; it performs no encryption at rest and cannot reference a Key Vault key. It is tempting because it protects sensitive data from unauthorised viewers, which is its actual purpose, but that scenario concerns query-result obfuscation, not TDE key management.
- ✗
Enable Azure Storage Service Encryption with a customer-managed key.
Why it's wrong here
Storage Service Encryption protects the underlying ADLS Gen2 storage account, not the dedicated SQL pool's own data files, so a Key Vault customer-managed key applied there does not encrypt the pool at rest. It is tempting because it is the correct approach for storage-account encryption with customer-managed keys.
- ✓
Enable Transparent Data Encryption (TDE) with a customer-managed key in Azure Key Vault.
Why this is correct
Transparent Data Encryption operates at the storage layer, encrypting data and log files at rest, and supports a customer-managed key held in Azure Key Vault — satisfying the stem's requirement that the dedicated SQL pool's data at rest be encrypted under organisational key control.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every DP-203 question from scratch — 509 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This DP-203 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-203 exam.