Courseiva
Implement a secure environmenthardMultiple SelectObjective-mapped

DP-300 Implement a secure environment Practice Question

You are a database administrator for a manufacturing company that uses Azure SQL Database. The company has a requirement to encrypt sensitive data in transit between the application and the database. Additionally, the company wants to ensure that database administrators (DBAs) cannot view the sensitive data. Which TWO features should you implement?

⚠ Common exam trap

A common mix-up: candidates confuse encryption at rest (TDE) or access control (RLS, masking) with encryption in transit and client-side encryption, leading them to select TDE or dynamic data masking instead of the correct combination of TLS enforcement and Always Encrypted.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Configure the server to enforce TLS 1.2 by setting the 'Minimal TLS Version' property

Configuring the server to enforce TLS 1.2 by setting the 'Minimal TLS Version' property ensures that all connections to Azure SQL Database use at least TLS 1.2, which encrypts data in transit. This directly addresses the requirement to encrypt sensitive data between the application and the database. Option E is correct because Always Encrypted with a column master key stored in Azure Key Vault ensures that sensitive data is encrypted at the client side and the encryption keys are never exposed to the database engine, preventing DBAs from viewing the sensitive data.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Implement row-level security (RLS) to filter rows

    Why it's wrong here

    RLS does not encrypt data and can be bypassed by users with elevated permissions.

  • Enable transparent data encryption (TDE) on the database

    Why it's wrong here

    TDE encrypts data at rest, but DBAs with access to the server can still see the data when queried.

  • Configure the server to enforce TLS 1.2 by setting the 'Minimal TLS Version' property

    Why this is correct

    This ensures all connections use TLS 1.2, encrypting data in transit.

  • Implement dynamic data masking on sensitive columns

    Why it's wrong here

    Dynamic data masking is bypassed by users with db_owner or CONTROL permissions, such as DBAs.

  • Use Always Encrypted with a column master key stored in Azure Key Vault

    Why this is correct

    Always Encrypted encrypts data in transit and at rest, and the encryption keys are stored in Azure Key Vault, inaccessible to DBAs.

About these practice questions

This DP-300 question is part of Courseiva's 906-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DP-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-300 exam.