Courseiva

DP-300 Plan and implement data platform resources Practice Question

You are a database administrator for a financial services company that uses Azure SQL Database. The company must ensure that all database backups are encrypted with a customer-managed key stored in Azure Key Vault. You need to configure the database to meet this requirement. What should you do first?

⚠ Common exam trap

A common mix-up: candidates confuse security features like auditing or Advanced Threat Protection with encryption key management, which are separate concerns.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create an Azure Key Vault and generate or import a key.

To use a customer-managed key for TDE, the key must exist in Azure Key Vault and the Azure SQL logical server must be granted permissions to access it. Creating the key vault and key is the necessary first step before enabling TDE with that key. Other options are security features but do not directly enable customer-managed key encryption.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Create an Azure Key Vault and generate or import a key.

    Why this is correct

    Before you can use a customer-managed key for TDE, you must have a key in Azure Key Vault. This involves creating a key vault, generating or importing a key, and granting the Azure SQL logical server access to the vault. This is the foundational step to enable TDE with customer-managed keys, ensuring compliance with the requirement.

  • ✗

    Enable transparent data encryption (TDE) with a service-managed key.

    Why it's wrong here

    Enabling TDE with a service-managed key encrypts the database at rest, but the key is managed by Microsoft, not the customer. The requirement specifies customer-managed keys, so this does not meet the compliance need. You must first configure the key in Azure Key Vault and then enable TDE with that key.

  • ✗

    Configure Azure SQL Database auditing to log all access to the database.

    Why it's wrong here

    Auditing tracks database events and writes them to an audit log, but it does not encrypt backups or manage encryption keys. While auditing is important for security monitoring, it does not fulfill the requirement of encrypting backups with a customer-managed key. The focus should be on setting up the key infrastructure first.

  • ✗

    Enable Advanced Threat Protection on the Azure SQL server.

    Why it's wrong here

    Advanced Threat Protection detects anomalous activities and potential threats, but it does not provide encryption or key management. It is a security monitoring feature, not an encryption mechanism. Therefore, it does not address the need for customer-managed key encryption for backups.

Go deeper

Related to this question

About these practice questions

One of 574 original DP-300 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This DP-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-300 exam.