DP-300 Implement a secure environment Practice Question
You are the database administrator for an Azure SQL Database that contains a column storing national ID numbers. A new regulation requires that this column be hidden from users who run ad hoc queries in the Azure portal Query Editor, while still being available to the payroll application. The payroll application connects with a login that has SELECT permission on the table. What should you implement?
⚠ Common exam trap
The trap here is reaching for encryption or views when the requirement is permission-based display masking, which dynamic data masking provides without changing the stored data or application code.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Apply dynamic data masking to the national ID column and grant UNMASK to the payroll application's user.
Dynamic data masking is designed to limit exposure of sensitive columns to users without the UNMASK permission while preserving the actual stored values. Granting UNMASK to the payroll application's user allows that workload to read real data, and portal users without UNMASK see masked results, matching the regulation and application needs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a view that excludes the national ID column and grant the ad hoc users SELECT on the view only.
Why it's wrong here
A view can hide a column, but ad hoc users with existing table permissions could still query the base table directly. It also requires revoking existing permissions and does not automatically mask values for arbitrary queries, so it is more fragile than the masking feature.
- ✓
Apply dynamic data masking to the national ID column and grant UNMASK to the payroll application's user.
Why this is correct
Dynamic data masking hides the column values from users without the UNMASK permission while leaving the data intact. Granting UNMASK to the payroll user lets that application see real values, and ad hoc users without UNMASK see masked output, satisfying both requirements without altering stored data.
- ✗
Enable row-level security on the table with a predicate that filters rows where the national ID is present.
Why it's wrong here
Row-level security filters which rows a user can see, not which columns. It would hide entire rows rather than mask a column value, and the payroll application needs the rows, so this approach both fails the requirement and disrupts legitimate access.
- ✗
Encrypt the national ID column with Always Encrypted and share the column master key with the payroll application.
Why it's wrong here
Always Encrypted protects data at rest and in transit to the client but requires application changes and key management. It does not selectively hide values from ad hoc portal users based on permission, and the Query Editor cannot decrypt the column, so it does not meet the masking requirement cleanly.
Go deeper
Related to this question
Learn chapter
Optimizing Database Query and Index Performance
Key term
Azure SQL Performance Tuning
Azure SQL Performance Tuning is the process of optimizing the speed and efficiency of queries and database operations in Microsoft Azure SQL Database or SQL Managed Instance to reduce latency and improve throughput.
About these practice questions
Courseiva writes every DP-300 question from scratch — 574 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This DP-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-300 exam.