DP-300 Implement a secure environment Practice Question
You are the database administrator for an Azure SQL Database that contains several tables with columns that store personally identifiable information (PII). The security team requires that these columns be identified and labeled as 'Confidential' in the database. You need to implement a solution that automatically classifies these columns based on their names and data patterns. What should you use?
⚠ Common exam trap
A common mix-up: candidates confuse data protection features like DDM or Always Encrypted with data discovery and classification, which is a separate capability for identifying and labeling sensitive data.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SQL Data Discovery and Classification.
SQL Data Discovery and Classification is the built-in feature in Azure SQL Database that scans for potentially sensitive columns, such as those containing PII, and allows you to apply classification labels like 'Confidential'. It uses pattern matching and column names to provide recommendations, which can be reviewed and applied. This directly meets the requirement to identify and label PII columns.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
SQL Data Discovery and Classification.
Why this is correct
SQL Data Discovery and Classification is a feature in Azure SQL Database that scans your database, identifies columns that may contain sensitive data based on names and data patterns, and allows you to apply classification labels such as 'Confidential'. It provides recommendations and can automatically classify columns, meeting the requirement to identify and label PII columns.
- ✗
Always Encrypted.
Why it's wrong here
Always Encrypted encrypts data at the client side to protect it from high-privileged users, but it does not classify or label columns. It is an encryption feature and does not provide discovery or labeling capabilities. Always Encrypted requires manual configuration of encryption keys and columns, not automatic classification.
- ✗
Transparent Data Encryption (TDE).
Why it's wrong here
TDE encrypts data at rest and does not classify or label columns. It is a storage-level encryption feature that protects database files and backups. TDE does not scan for PII or apply classification labels; it is unrelated to data discovery and classification requirements.
- ✗
Dynamic Data Masking (DDM).
Why it's wrong here
DDM masks sensitive data in query results for non-privileged users but does not classify or label columns. It is a data protection feature, not a data discovery or classification tool. DDM does not scan for PII or apply labels; it only obscures data at the presentation layer.
Go deeper
Related to this question
Learn chapter
Securing Data at Rest and in Transit
Key term
Azure SQL Performance Tuning
Azure SQL Performance Tuning is the process of optimizing the speed and efficiency of queries and database operations in Microsoft Azure SQL Database or SQL Managed Instance to reduce latency and improve throughput.
About these practice questions
Courseiva writes every DP-300 question from scratch — 574 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This DP-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-300 exam.