DP-300 Implement a secure environment Practice Question
You are deploying an Azure SQL Database that will contain highly sensitive personal data. The security policy requires that the data be encrypted at rest, in transit, and in use. Additionally, the encryption keys must be stored in a hardware security module (HSM) and be customer-managed. Which combination of features should you implement?
⚠ Common exam trap
Many exam-takers confuse Dynamic Data Masking with encryption in use, or overlook that storing keys in Key Vault does not automatically imply HSM protection unless the vault is specifically HSM-backed.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
TDE with a customer-managed key in Azure Key Vault (HSM-backed), enforce TLS 1.2, and Always Encrypted with a column master key in Azure Key Vault (HSM-backed).
It satisfies all requirements: encryption at rest via TDE with a customer-managed key stored in an HSM-backed Key Vault, encryption in transit by enforcing TLS 1.2, and encryption in use via Always Encrypted with the column master key also stored in an HSM-backed Key Vault. This ensures that all three states of data are encrypted and that keys are both customer-managed and hardware-protected.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
TDE with a service-managed key, enforce TLS 1.2, and Always Encrypted with a column master key in Key Vault.
Why it's wrong here
A service-managed key cannot satisfy the customer-managed requirement, and Key Vault, not a hardware security module, holds the column master key. Always Encrypted does provide in-use encryption. This combination suits scenarios where operational simplicity is prioritised over key custody requirements.
- ✗
TDE with a customer-managed key in Key Vault, enforce TLS 1.2, and use Dynamic Data Masking.
Why it's wrong here
Dynamic Data Masking only obscures query results at presentation; it does not encrypt data in use, so the in-use requirement fails. TDE with a customer-managed key and TLS 1.2 do meet the at-rest and in-transit requirements. Masking suits limiting exposure to non-privileged query users.
- ✗
TDE with a customer-managed key in Key Vault, enforce TLS 1.2, and Always Encrypted with a column master key stored in Windows Certificate Store.
Why it's wrong here
The Windows Certificate Store is not a hardware security module, so the column master key fails the HSM custody requirement. TDE with a customer-managed key and TLS 1.2 satisfy at-rest and in-transit encryption. Certificate Store custody suits deployments without Azure Key Vault access.
- ✓
TDE with a customer-managed key in Azure Key Vault (HSM-backed), enforce TLS 1.2, and Always Encrypted with a column master key in Azure Key Vault (HSM-backed).
Why this is correct
TDE with a customer-managed HSM-backed key in Azure Key Vault covers encryption at rest, enforced TLS 1.2 secures data in transit, and Always Encrypted with an HSM-backed column master key protects data in use. This satisfies all three encryption states plus customer-managed HSM keys.
Go deeper
Related to this question
Learn chapter
Deploying and Configuring Azure SQL Database
Key term
Azure SQL Performance Tuning
Azure SQL Performance Tuning is the process of optimizing the speed and efficiency of queries and database operations in Microsoft Azure SQL Database or SQL Managed Instance to reduce latency and improve throughput.
Key term
Transparent Data Encryption
Transparent Data Encryption is a security feature that automatically encrypts data written to a database and decrypts it when read, without requiring any changes to the application.
About these practice questions
This DP-300 question is part of Courseiva's 574-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DP-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-300 exam.