DP-300 Implement a secure environment Practice Question
You are a database administrator for a manufacturing company that uses Azure SQL Database. The company has a requirement to encrypt sensitive data in transit between the application and the database. Additionally, the company wants to ensure that database administrators (DBAs) cannot view the sensitive data. Which TWO features should you implement?
⚠ Common exam trap
A common mix-up: candidates confuse encryption at rest (TDE) or access control (RLS, masking) with encryption in transit and client-side encryption, leading them to select TDE or dynamic data masking instead of the correct combination of TLS enforcement and Always Encrypted.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure the server to enforce TLS 1.2 by setting the 'Minimal TLS Version' property
Option C is correct because setting the server's 'Minimal TLS Version' property to 1.2 forces all client connections to Azure SQL Database to negotiate TLS 1.2, which encrypts data in transit between the application and the database. Option E is correct because Always Encrypted encrypts sensitive column data on the client side using a column master key stored in Azure Key Vault, so the data is never decrypted on the SQL server and DBAs cannot view the plaintext. Option A is incorrect because row-level security only filters which rows a user can access; it does not encrypt data in transit or hide column values from DBAs. Option B is incorrect because TDE encrypts data at rest (database, log, and backup files) and does not protect data in transit, nor does it prevent DBAs from viewing data since they can still query decrypted values. Option D is incorrect because dynamic data masking only obscures data in query results for non-privileged users and does not encrypt data in transit or prevent DBAs, who can be granted UNMASK permission, from viewing the actual data.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Implement row-level security (RLS) to filter rows
Why it's wrong here
Row-level security filters which rows a principal retrieves; it neither encrypts data in transit nor hides column contents from a DBA who can query with elevated permissions. RLS suits multi-tenant row isolation, while Always Encrypted with column master keys in the client satisfies both stated requirements.
- ✗
Enable transparent data encryption (TDE) on the database
Why it's wrong here
Transparent data encryption protects data at rest, encrypting database, log and backup files, but data in transit still relies on TLS and DBAs retain plaintext visibility through normal queries. TDE suits compliance for stored media; Always Encrypted addresses both the transit and administrator-visibility requirements here.
- ✓
Configure the server to enforce TLS 1.2 by setting the 'Minimal TLS Version' property
Why this is correct
Enforcing TLS 1.2 via the Minimal TLS Version property encrypts data in transit between application and server, satisfying the in-transit encryption requirement. It does not hide data from DBAs, so it must pair with Always Encrypted to meet the second constraint.
- ✗
Implement dynamic data masking on sensitive columns
Why it's wrong here
Dynamic data masking rewrites query results for non-privileged users but leaves stored values readable, and DBAs can be granted UNMASK, so it cannot prevent administrator viewing. Masking suits presentation-layer obfuscation for application users, whereas Always Encrypted keeps ciphertext opaque to the database engine itself.
- ✓
Use Always Encrypted with a column master key stored in Azure Key Vault
Why this is correct
Always Encrypted encrypts column data client-side, so the column master key held in Azure Key Vault is never exposed to the database engine. DBAs therefore see only ciphertext, satisfying the requirement that administrators cannot view sensitive data.
Go deeper
Related to this question
Learn chapter
Optimizing Database Query and Index Performance
Key term
Transparent Data Encryption
Transparent Data Encryption is a security feature that automatically encrypts data written to a database and decrypts it when read, without requiring any changes to the application.
Key term
Azure SQL Performance Tuning
Azure SQL Performance Tuning is the process of optimizing the speed and efficiency of queries and database operations in Microsoft Azure SQL Database or SQL Managed Instance to reduce latency and improve throughput.
About these practice questions
This DP-300 question is part of Courseiva's 574-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DP-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-300 exam.