Courseiva

DP-300 Implement a secure environment Practice Question

You are the database administrator for a company that uses Azure SQL Database. The company has a policy that database administrators must not have access to sensitive data in a specific table named EmployeeSalaries. You need to implement a solution that allows DBAs to manage the database but prevents them from viewing or modifying data in the EmployeeSalaries table. What should you implement?

⚠ Common exam trap

The trap here is assuming that DDM or RLS can restrict DBAs, but these features are bypassed by users with elevated permissions like sysadmin or db_owner.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Always Encrypted with column encryption keys stored in Azure Key Vault, and restrict DBA access to the keys.

Always Encrypted is designed to protect sensitive data from high-privileged users like DBAs by ensuring that encryption and decryption occur on the client side. The database engine never sees the plaintext data or the encryption keys. By storing the column encryption keys in Azure Key Vault and not granting DBAs access to the keys, DBAs cannot view or modify the data, even with sysadmin privileges. This meets the policy requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Dynamic Data Masking (DDM) on the sensitive columns.

    Why it's wrong here

    DDM masks data for non-privileged users but does not prevent privileged users like DBAs from viewing the actual data. DBAs can still see unmasked data because they have the UNMASK permission. DDM is a presentation-layer feature and does not provide true access control for administrators.

  • ✓

    Always Encrypted with column encryption keys stored in Azure Key Vault, and restrict DBA access to the keys.

    Why this is correct

    Always Encrypted ensures that data is encrypted at the client and never revealed to the database engine. By storing the column encryption keys in Azure Key Vault and not granting DBAs access to the keys, DBAs cannot decrypt the data even if they have full database permissions. This satisfies the requirement to prevent DBAs from viewing or modifying sensitive data.

  • ✗

    Transparent Data Encryption (TDE) with a customer-managed key.

    Why it's wrong here

    TDE encrypts data at rest and is transparent to users, including DBAs. DBAs can still query and see the data in plaintext because TDE decrypts data when accessed. It does not prevent DBAs from viewing or modifying data. TDE protects against physical theft of files, not against privileged users.

  • ✗

    Row-Level Security (RLS) with a filter predicate that excludes DBAs.

    Why it's wrong here

    RLS filters rows based on user identity, but it does not prevent users with control permissions (like DBAs) from disabling or altering the security policy. DBAs can modify the policy or use other means to access data. RLS is not designed to restrict administrators who have high-level permissions.

About these practice questions

Courseiva writes every DP-300 question from scratch — 574 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This DP-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-300 exam.