Courseiva
Implement a secure environmenthardMultiple SelectObjective-mapped

DP-300 Implement a secure environment Practice Question

You are deploying a new Azure SQL Database that will store Personally Identifiable Information (PII). You need to ensure that the data is encrypted at rest and that access to encryption keys is logged. Which THREE actions should you take? (Choose three.)

⚠ Common exam trap

Candidates often confuse Always Encrypted with TDE, selecting Always Encrypted for at-rest encryption when it is actually designed for client-side encryption of sensitive columns, not for full database-level encryption at rest.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Grant the managed identity of the database access to the key vault with 'get', 'wrapKey', and 'unwrapKey' permissions.

To use customer-managed TDE keys stored in Azure Key Vault, the Azure SQL Database's managed identity must be granted 'get', 'wrapKey', and 'unwrapKey' permissions. This allows the database to access the key for encryption and decryption operations while maintaining a secure, auditable key management chain.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Use Always Encrypted to encrypt all PII columns.

    Why it's wrong here

    Always Encrypted encrypts specific columns, not the entire database; TDE is required for full at-rest encryption.

  • Grant the managed identity of the database access to the key vault with 'get', 'wrapKey', and 'unwrapKey' permissions.

    Why this is correct

    This is necessary for TDE with CMK to access the encryption key.

  • Configure TDE with service-managed keys.

    Why it's wrong here

    Service-managed keys do not allow logging of key access because Microsoft manages the keys.

  • Enable Transparent Data Encryption (TDE) with customer-managed keys in Azure Key Vault.

    Why this is correct

    TDE with CMK encrypts the database at rest and allows logging key access via Key Vault audit logs.

  • Enable auditing on the Azure Key Vault to log key operations.

    Why this is correct

    Key Vault auditing logs all access to keys, including get, wrap, and unwrap operations.

Go deeper

Related to this question

About these practice questions

One of 906 original DP-300 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DP-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-300 exam.