Courseiva

DP-300 Plan and implement data platform resources Practice Question

Which TWO actions are required to implement transparent data encryption (TDE) with customer-managed keys for an Azure SQL Database?

⚠ Common exam trap

A common mix-up: candidates confuse TDE with Always Encrypted or on-premises certificate-based TDE, leading them to select options about column encryption keys or server certificates, which are not part of Azure SQL Database TDE implementation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create an Azure Key Vault and a key.

Option A is correct because implementing TDE with customer-managed keys (BYOK) requires an Azure Key Vault (or Managed HSM) to hold the asymmetric RSA key that protects the database encryption key; the vault must be created and the key generated before it can be referenced. Option B is correct because the key must be assigned to the Azure SQL logical server (via the server's TDE protector, e.g., Set-AzSqlServerTransparentDataEncryptionProtector or the portal's Transparent data encryption blade) and TDE then enabled so the server uses that customer-managed key as the protector for its databases. Option C is not required because backup encryption in Azure SQL is automatic and tied to TDE; there is no separate 'Encrypted' backup encryption level setting to configure. Option D is not required because server certificates are a SQL Server on-premises/IaaS mechanism, not how Azure SQL Database BYOK is implemented. Option E is not required because column encryption keys belong to Always Encrypted, a different feature from TDE.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Create an Azure Key Vault and a key.

    Why this is correct

    Customer-managed TDE requires an Azure Key Vault holding the asymmetric key that wraps the database encryption protector. Creating the vault and key is the prerequisite step before the SQL logical server can reference it, satisfying the stem's customer-managed key constraint.

  • ✓

    Assign the key to the Azure SQL logical server and enable TDE.

    Why this is correct

    The database encryption protector must point to the key, so you assign the Key Vault key to the Azure SQL logical server's identity and enable TDE. This binds the server-level protector to your customer-managed key, completing the second required action.

  • ✗

    Set the backup encryption level to 'Encrypted'.

    Why it's wrong here

    Backup encryption level is a setting on the database's backup storage redundancy and does not provision or wrap the TDE protector key. It is tempting because TDE encrypts backups as a side effect, but customer-managed TDE requires a key vault key and a server-level key reference instead.

  • ✗

    Create a server certificate in the database.

    Why it's wrong here

    Azure SQL Database has no server certificate construct; TDE keys are asymmetric keys held in Azure Key Vault and referenced by the logical server. It is tempting because on-premises SQL Server uses a server certificate to protect the database encryption key, but that mechanism does not exist in the Azure service.

  • ✗

    Configure column encryption keys in the database.

    Why it's wrong here

    Column encryption keys belong to Always Encrypted, which protects individual columns client-side, not the database's data-at-rest pages. It is tempting because both features involve encryption keys and the word 'encryption', but TDE needs an asymmetric key in Azure Key Vault, not column master or column encryption keys.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

Go deeper

Related to this question

About these practice questions

Courseiva writes every DP-300 question from scratch — 574 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DP-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-300 exam.