Courseiva

DP-300 Implement a secure environment Practice Question

You administer an Azure SQL Database that contains a table named dbo.Employees with columns for Social Security Number and salary. Company policy requires that support staff querying the table see only the last four digits of the Social Security Number and a masked salary value, while the payroll application, which connects with a different login, must see the actual values. You need to implement this with the least administrative effort and without changing the application queries. What should you do?

⚠ Common exam trap

The trap here is choosing Always Encrypted or row-level security to limit visibility, when only Dynamic Data Masking provides partial value masking without changing queries.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Apply Dynamic Data Masking rules to the SSN and salary columns and grant the support staff login SELECT on the table.

Dynamic Data Masking is designed for exactly this scenario: it masks column values for users who lack the UNMASK permission while leaving the data intact and visible to privileged logins. Because masking is applied by the engine during query execution, no application changes are needed, and the payroll login with UNMASK sees the real values.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Apply Dynamic Data Masking rules to the SSN and salary columns and grant the support staff login SELECT on the table.

    Why this is correct

    Dynamic Data Masking applies masking at query time for users without the UNMASK permission, while privileged logins retain full visibility. Because masking is transparent to the query text and enforced in the engine, support staff see masked values and the payroll login sees real values without any application changes.

  • ✗

    Encrypt the SSN and salary columns with Always Encrypted and distribute the column master key only to the payroll application.

    Why it's wrong here

    Always Encrypted would prevent support staff from reading the values at all rather than showing masked versions, and it typically requires connection string changes and driver support. The requirement is partial visibility, not encryption, so this approach both over-restricts access and increases application complexity.

  • ✗

    Create a view that returns masked values and grant support staff SELECT on the view instead of the table.

    Why it's wrong here

    A view can return masked expressions, but it requires support staff to query the view rather than the table and requires you to manage grants carefully so they cannot bypass the view. It also changes the object name in queries, which conflicts with the requirement to avoid application changes and adds administrative overhead.

  • ✗

    Create a row-level security policy that filters rows based on the support staff login.

    Why it's wrong here

    Row-level security controls which rows a user can see, not which column values are displayed. Support staff would either see entire rows with the real SSN and salary or no rows at all. It cannot produce a partially masked value such as the last four digits, so it does not meet the requirement.

About these practice questions

This DP-300 question is part of Courseiva's 574-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This DP-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-300 exam.