DP-300 Plan and implement data platform resources Practice Question
Which TWO actions are required to implement transparent data encryption (TDE) with customer-managed keys for an Azure SQL Database?
⚠ Common exam trap
A common mix-up: candidates confuse TDE with Always Encrypted or on-premises certificate-based TDE, leading them to select options about column encryption keys or server certificates, which are not part of Azure SQL Database TDE implementation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an Azure Key Vault and a key.
Option A is correct because implementing TDE with customer-managed keys (BYOK) requires an Azure Key Vault (or Managed HSM) to hold the asymmetric RSA key that protects the database encryption key; the vault must be created and the key generated before it can be referenced. Option B is correct because the key must be assigned to the Azure SQL logical server (via the server's TDE protector, e.g., Set-AzSqlServerTransparentDataEncryptionProtector or the portal's Transparent data encryption blade) and TDE then enabled so the server uses that customer-managed key as the protector for its databases. Option C is not required because backup encryption in Azure SQL is automatic and tied to TDE; there is no separate 'Encrypted' backup encryption level setting to configure. Option D is not required because server certificates are a SQL Server on-premises/IaaS mechanism, not how Azure SQL Database BYOK is implemented. Option E is not required because column encryption keys belong to Always Encrypted, a different feature from TDE.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create an Azure Key Vault and a key.
Why this is correct
Customer-managed TDE requires an Azure Key Vault holding the asymmetric key that wraps the database encryption protector. Creating the vault and key is the prerequisite step before the SQL logical server can reference it, satisfying the stem's customer-managed key constraint.
- ✓
Assign the key to the Azure SQL logical server and enable TDE.
Why this is correct
The database encryption protector must point to the key, so you assign the Key Vault key to the Azure SQL logical server's identity and enable TDE. This binds the server-level protector to your customer-managed key, completing the second required action.
- ✗
Set the backup encryption level to 'Encrypted'.
Why it's wrong here
Backup encryption level is a setting on the database's backup storage redundancy and does not provision or wrap the TDE protector key. It is tempting because TDE encrypts backups as a side effect, but customer-managed TDE requires a key vault key and a server-level key reference instead.
- ✗
Create a server certificate in the database.
Why it's wrong here
Azure SQL Database has no server certificate construct; TDE keys are asymmetric keys held in Azure Key Vault and referenced by the logical server. It is tempting because on-premises SQL Server uses a server certificate to protect the database encryption key, but that mechanism does not exist in the Azure service.
- ✗
Configure column encryption keys in the database.
Why it's wrong here
Column encryption keys belong to Always Encrypted, which protects individual columns client-side, not the database's data-at-rest pages. It is tempting because both features involve encryption keys and the word 'encryption', but TDE needs an asymmetric key in Azure Key Vault, not column master or column encryption keys.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
Learn chapter
Migrating On-Premises Databases to Azure
Key term
Transparent Data Encryption
Transparent Data Encryption is a security feature that automatically encrypts data written to a database and decrypts it when read, without requiring any changes to the application.
Key term
Azure SQL Performance Tuning
Azure SQL Performance Tuning is the process of optimizing the speed and efficiency of queries and database operations in Microsoft Azure SQL Database or SQL Managed Instance to reduce latency and improve throughput.
About these practice questions
Courseiva writes every DP-300 question from scratch — 574 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DP-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-300 exam.