DP-300 Implement a secure environment Practice Question
You administer an Azure SQL Database named HRDB. The security team requires that all data written to the database be encrypted with a customer-managed key that is stored in Azure Key Vault, and that the key be automatically rotated every 90 days. You need to configure Transparent Data Encryption (TDE) with Bring Your Own Key (BYOK). What should you do first?
⚠ Common exam trap
Many exam-takers confuse Always Encrypted with TDE BYOK, or assuming the existing TDE protector can be exported.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an Azure Key Vault with purge protection enabled and grant the logical server's managed identity the Key Vault Crypto Service Encryption User role.
To configure TDE with BYOK, you first need an Azure Key Vault with purge protection enabled and the logical server's managed identity granted the appropriate Key Vault Crypto Service Encryption User role. This allows the server to access and use the key as the TDE protector. Without this prerequisite, the key cannot be used for encryption.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable Always Encrypted on all columns in HRDB to use the customer-managed key.
Why it's wrong here
Always Encrypted is a client-side encryption feature that protects individual columns and requires application changes. It does not satisfy the requirement for TDE with BYOK, which encrypts the entire database at rest. The scenario specifically asks for TDE BYOK, so Always Encrypted is the wrong technology.
- ✗
Export the existing TDE protector from the master database and upload it to Azure Key Vault.
Why it's wrong here
The existing TDE protector is a service-managed certificate or key that cannot be exported from Azure SQL Database. BYOK requires creating a new key in Azure Key Vault or importing a customer-generated key, not exporting the platform-managed protector. This approach is not supported for Azure SQL Database.
- ✓
Create an Azure Key Vault with purge protection enabled and grant the logical server's managed identity the Key Vault Crypto Service Encryption User role.
Why this is correct
TDE with BYOK requires the logical server to access the key. The server's system-assigned managed identity must be granted the Key Vault Crypto Service Encryption User role, and the vault must have purge protection enabled to prevent accidental key deletion. This is the prerequisite before configuring the key as the TDE protector.
- ✗
Create a database-scoped credential that references the Azure Key Vault key and assign it to the database.
Why it's wrong here
A database-scoped credential is used for external data sources such as Elastic Query or PolyBase, not for TDE. TDE BYOK is configured at the server level using the server's managed identity, not a database-scoped credential. This option does not meet the requirement.
Go deeper
Related to this question
Learn chapter
Managing Identity and Access for Azure SQL
Key term
Transparent Data Encryption
Transparent Data Encryption is a security feature that automatically encrypts data written to a database and decrypts it when read, without requiring any changes to the application.
Key term
Azure SQL Performance Tuning
Azure SQL Performance Tuning is the process of optimizing the speed and efficiency of queries and database operations in Microsoft Azure SQL Database or SQL Managed Instance to reduce latency and improve throughput.
About these practice questions
This DP-300 question is part of Courseiva's 574-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This DP-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-300 exam.