DP-300 Implement a secure environment Practice Question
You are configuring security for an Azure SQL Database. The security policy requires that all connections to the database must be encrypted and that the encryption keys must be managed by your organization. You need to implement Transparent Data Encryption (TDE) with a customer-managed key (CMK) stored in Azure Key Vault. What should you do first?
⚠ Common exam trap
The trap here is thinking that you must first enable TDE with a service-managed key before switching to a customer-managed key, or that on-premises concepts like database master keys apply directly to Azure SQL Database TDE.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an Azure Key Vault and grant the Azure SQL logical server's managed identity the get, wrapKey, and unwrapKey permissions on the key.
For TDE with customer-managed keys in Azure SQL Database, the first step is to set up Azure Key Vault and grant the logical server's managed identity the required permissions to access the key. This enables the server to use the key for encryption. Once this is done, you can configure TDE to use the customer-managed key. The other options either do not meet the key management requirement or are not applicable.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create an Azure Key Vault and grant the Azure SQL logical server's managed identity the get, wrapKey, and unwrapKey permissions on the key.
Why this is correct
To use a customer-managed key for TDE, you must first create an Azure Key Vault, generate or import a key, and then grant the Azure SQL logical server's managed identity the necessary permissions (get, wrapKey, unwrapKey) to access that key. This allows the server to use the key for TDE operations. This is the foundational step before configuring TDE to use the key.
- ✗
Configure a firewall rule to allow connections from your organization's IP addresses.
Why it's wrong here
Firewall rules control network access, not encryption key management. They are unrelated to TDE with customer-managed keys. While important for security, they do not fulfill the requirement of using a customer-managed key for TDE. This option is a distractor based on general security configuration.
- ✗
Create a database master key (DMK) in the master database of the Azure SQL logical server.
Why it's wrong here
In Azure SQL Database, the database master key is managed by the platform and you cannot create it manually in the master database. TDE with customer-managed keys uses Azure Key Vault, not a DMK in the master database. This option reflects an on-premises SQL Server concept that does not apply directly to Azure SQL Database TDE with CMK.
- ✗
Enable TDE on the database using the default service-managed key.
Why it's wrong here
Enabling TDE with the default service-managed key does not meet the requirement for customer-managed keys. While it encrypts the database, the keys are managed by Microsoft. You would later need to switch to a customer-managed key, but this step is not necessary and adds extra work. The requirement explicitly states keys must be managed by your organization.
Go deeper
Related to this question
Learn chapter
Deploying and Configuring Azure SQL Managed Instance
Key term
Azure SQL Performance Tuning
Azure SQL Performance Tuning is the process of optimizing the speed and efficiency of queries and database operations in Microsoft Azure SQL Database or SQL Managed Instance to reduce latency and improve throughput.
Key term
Transparent Data Encryption
Transparent Data Encryption is a security feature that automatically encrypts data written to a database and decrypts it when read, without requiring any changes to the application.
About these practice questions
Courseiva writes every DP-300 question from scratch — 574 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This DP-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-300 exam.