You are the DBA for an Azure SQL Database named OrdersDB. The security team requires that you implement row-level security (RLS) to ensure that sales representatives can only view orders for their own region. You need to create a security policy that filters rows based on the sales representative's region. Which two actions should you perform? (Choose two.)
A predicate function is required for RLS. An inline table-valued function that returns 1 when the user's region matches the row's region is used as the filter predicate in the security policy. This function enforces the row filtering logic based on the current user's region.
Why this answer
Row-level security in Azure SQL Database requires a predicate function that defines the filtering logic and a security policy that applies that function to the table. The inline table-valued function returns 1 when the row should be visible to the user, and the security policy adds a FILTER PREDICATE using that function. Together, they enforce that sales representatives only see orders for their region.
Other actions do not implement RLS.
Exam trap
The trap here is thinking that granting permissions or creating roles alone achieves row-level security, when the essential components are the predicate function and the security policy.