Courseiva

DP-300 Plan and implement data platform resources Practice Question

You are deploying an Azure SQL Database for a new application. The database must be encrypted at rest using Transparent Data Encryption (TDE) with a customer-managed key stored in Azure Key Vault. You need to ensure that the key is automatically rotated every 90 days and that the database remains accessible if the key is rotated. What should you configure?

⚠ Common exam trap

Many candidates confuse TDE with Always Encrypted or assuming that manual key updates are sufficient, when the requirement explicitly calls for automatic rotation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create an Azure Key Vault, generate a key, and configure the SQL server's TDE protector to use that key. Then set up a key rotation policy in Key Vault.

Configuring TDE with a customer-managed key in Azure Key Vault and setting a rotation policy in Key Vault enables automatic key rotation. Azure SQL Database automatically uses the latest key version when the key is rotated, provided the server is configured to use the latest version. This meets the 90-day rotation and continuous access requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use Always Encrypted with a column master key stored in Azure Key Vault and configure automatic rotation.

    Why it's wrong here

    Always Encrypted protects data in use and is not a substitute for TDE, which encrypts data at rest. The scenario specifically requires TDE with a customer-managed key. Always Encrypted does not encrypt the entire database at rest and does not fulfill the TDE requirement.

  • ✗

    Enable TDE with a service-managed key and configure automatic key rotation in the Azure portal.

    Why it's wrong here

    Service-managed keys are managed by Microsoft and do not support customer-controlled rotation schedules or the use of Azure Key Vault. The requirement explicitly states a customer-managed key stored in Key Vault, so using a service-managed key does not meet the security and compliance needs.

  • ✓

    Create an Azure Key Vault, generate a key, and configure the SQL server's TDE protector to use that key. Then set up a key rotation policy in Key Vault.

    Why this is correct

    To use a customer-managed key for TDE, you store the key in Azure Key Vault and set it as the TDE protector for the logical server. Key Vault supports rotation policies that automatically generate new key versions, and Azure SQL Database automatically uses the latest version if configured to do so, ensuring continuous access.

  • ✗

    Store the key in Azure Key Vault and manually update the TDE protector every 90 days using PowerShell scripts.

    Why it's wrong here

    While this approach uses a customer-managed key in Key Vault, it requires manual intervention and does not provide automatic rotation. The requirement is for automatic rotation every 90 days, so a manual process is error-prone and does not satisfy the automation need.

Go deeper

Related to this question

About these practice questions

This DP-300 question is part of Courseiva's 574-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This DP-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-300 exam.