DP-300 Implement a secure environment Practice Question
You administer an Azure SQL Database named HRDB. The security team requires that all data at rest be encrypted with a customer-managed key stored in Azure Key Vault, and that the key be automatically rotated every 90 days. You create the Key Vault and grant the logical server's managed identity the necessary permissions. What should you do next to meet the requirement?
⚠ Common exam trap
Many exam-takers confuse Always Encrypted with TDE, assuming any encryption feature satisfies the customer-managed key requirement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure TDE on the logical server to use a customer-managed key from Azure Key Vault and enable auto-rotation.
The requirement is for encryption at rest using a customer-managed key in Azure Key Vault with automatic rotation. TDE with a customer-managed key (BYOK) is the Azure SQL feature that provides this. Configuring TDE to use a Key Vault key and enabling auto-rotation ensures the key is rotated every 90 days without manual intervention, satisfying the security team's policy.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Configure TDE on the logical server to use a customer-managed key from Azure Key Vault and enable auto-rotation.
Why this is correct
Configuring TDE with a customer-managed key (BYOK) stored in Azure Key Vault meets the requirement for customer control. Azure SQL supports automatic key rotation when the key is set to auto-rotate in Key Vault, so the 90-day rotation requirement is satisfied without manual intervention.
- ✗
Enable Transparent Data Encryption (TDE) with a service-managed key on the logical server.
Why it's wrong here
Service-managed TDE keys are managed by Microsoft and cannot be rotated on a customer-defined 90-day schedule. This option does not provide customer control over the key or its rotation, so it fails the requirement for a customer-managed key in Azure Key Vault.
- ✗
Enable Dynamic Data Masking on all sensitive columns.
Why it's wrong here
Dynamic Data Masking only obfuscates data returned to non-privileged users; it does not encrypt data at rest. It cannot use Azure Key Vault keys and has no rotation mechanism, so it does not meet the encryption and key management requirements described.
- ✗
Enable Always Encrypted on all columns containing sensitive data.
Why it's wrong here
Always Encrypted protects data in use and in transit at the client side, but it does not satisfy the requirement for encryption at rest with a customer-managed key and automatic rotation. It also requires application changes and column-level configuration, which is not what the scenario asks for.
Go deeper
Related to this question
Learn chapter
Securing Data at Rest and in Transit
Key term
Transparent Data Encryption
Transparent Data Encryption is a security feature that automatically encrypts data written to a database and decrypts it when read, without requiring any changes to the application.
Key term
Azure SQL Performance Tuning
Azure SQL Performance Tuning is the process of optimizing the speed and efficiency of queries and database operations in Microsoft Azure SQL Database or SQL Managed Instance to reduce latency and improve throughput.
About these practice questions
One of 574 original DP-300 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This DP-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-300 exam.