Courseiva

DP-300 Implement a secure environment Practice Question

You are a database administrator for a manufacturing company that uses Azure SQL Database. The company has a requirement to encrypt sensitive data in transit between the application and the database. Additionally, the company wants to ensure that database administrators (DBAs) cannot view the sensitive data. Which TWO features should you implement?

⚠ Common exam trap

A common mix-up: candidates confuse encryption at rest (TDE) or access control (RLS, masking) with encryption in transit and client-side encryption, leading them to select TDE or dynamic data masking instead of the correct combination of TLS enforcement and Always Encrypted.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure the server to enforce TLS 1.2 by setting the 'Minimal TLS Version' property

Option C is correct because setting the server's 'Minimal TLS Version' property to 1.2 forces all client connections to Azure SQL Database to negotiate TLS 1.2, which encrypts data in transit between the application and the database. Option E is correct because Always Encrypted encrypts sensitive column data on the client side using a column master key stored in Azure Key Vault, so the data is never decrypted on the SQL server and DBAs cannot view the plaintext. Option A is incorrect because row-level security only filters which rows a user can access; it does not encrypt data in transit or hide column values from DBAs. Option B is incorrect because TDE encrypts data at rest (database, log, and backup files) and does not protect data in transit, nor does it prevent DBAs from viewing data since they can still query decrypted values. Option D is incorrect because dynamic data masking only obscures data in query results for non-privileged users and does not encrypt data in transit or prevent DBAs, who can be granted UNMASK permission, from viewing the actual data.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Implement row-level security (RLS) to filter rows

    Why it's wrong here

    Row-level security filters which rows a principal retrieves; it neither encrypts data in transit nor hides column contents from a DBA who can query with elevated permissions. RLS suits multi-tenant row isolation, while Always Encrypted with column master keys in the client satisfies both stated requirements.

  • ✗

    Enable transparent data encryption (TDE) on the database

    Why it's wrong here

    Transparent data encryption protects data at rest, encrypting database, log and backup files, but data in transit still relies on TLS and DBAs retain plaintext visibility through normal queries. TDE suits compliance for stored media; Always Encrypted addresses both the transit and administrator-visibility requirements here.

  • ✓

    Configure the server to enforce TLS 1.2 by setting the 'Minimal TLS Version' property

    Why this is correct

    Enforcing TLS 1.2 via the Minimal TLS Version property encrypts data in transit between application and server, satisfying the in-transit encryption requirement. It does not hide data from DBAs, so it must pair with Always Encrypted to meet the second constraint.

  • ✗

    Implement dynamic data masking on sensitive columns

    Why it's wrong here

    Dynamic data masking rewrites query results for non-privileged users but leaves stored values readable, and DBAs can be granted UNMASK, so it cannot prevent administrator viewing. Masking suits presentation-layer obfuscation for application users, whereas Always Encrypted keeps ciphertext opaque to the database engine itself.

  • ✓

    Use Always Encrypted with a column master key stored in Azure Key Vault

    Why this is correct

    Always Encrypted encrypts column data client-side, so the column master key held in Azure Key Vault is never exposed to the database engine. DBAs therefore see only ciphertext, satisfying the requirement that administrators cannot view sensitive data.

Go deeper

Related to this question

About these practice questions

This DP-300 question is part of Courseiva's 574-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DP-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-300 exam.