Courseiva

DP-300 Implement a secure environment Practice Question

You administer an Azure SQL Database named HRDB. The security team requires that all data written to the database be encrypted with a customer-managed key that is stored in Azure Key Vault, and that the key be automatically rotated every 90 days. You need to configure Transparent Data Encryption (TDE) with Bring Your Own Key (BYOK). What should you do first?

⚠ Common exam trap

Many exam-takers confuse Always Encrypted with TDE BYOK, or assuming the existing TDE protector can be exported.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create an Azure Key Vault with purge protection enabled and grant the logical server's managed identity the Key Vault Crypto Service Encryption User role.

To configure TDE with BYOK, you first need an Azure Key Vault with purge protection enabled and the logical server's managed identity granted the appropriate Key Vault Crypto Service Encryption User role. This allows the server to access and use the key as the TDE protector. Without this prerequisite, the key cannot be used for encryption.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable Always Encrypted on all columns in HRDB to use the customer-managed key.

    Why it's wrong here

    Always Encrypted is a client-side encryption feature that protects individual columns and requires application changes. It does not satisfy the requirement for TDE with BYOK, which encrypts the entire database at rest. The scenario specifically asks for TDE BYOK, so Always Encrypted is the wrong technology.

  • ✗

    Export the existing TDE protector from the master database and upload it to Azure Key Vault.

    Why it's wrong here

    The existing TDE protector is a service-managed certificate or key that cannot be exported from Azure SQL Database. BYOK requires creating a new key in Azure Key Vault or importing a customer-generated key, not exporting the platform-managed protector. This approach is not supported for Azure SQL Database.

  • ✓

    Create an Azure Key Vault with purge protection enabled and grant the logical server's managed identity the Key Vault Crypto Service Encryption User role.

    Why this is correct

    TDE with BYOK requires the logical server to access the key. The server's system-assigned managed identity must be granted the Key Vault Crypto Service Encryption User role, and the vault must have purge protection enabled to prevent accidental key deletion. This is the prerequisite before configuring the key as the TDE protector.

  • ✗

    Create a database-scoped credential that references the Azure Key Vault key and assign it to the database.

    Why it's wrong here

    A database-scoped credential is used for external data sources such as Elastic Query or PolyBase, not for TDE. TDE BYOK is configured at the server level using the server's managed identity, not a database-scoped credential. This option does not meet the requirement.

Go deeper

Related to this question

About these practice questions

This DP-300 question is part of Courseiva's 574-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This DP-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-300 exam.