Courseiva

DP-300 Implement a secure environment Practice Question

You are the database administrator for an Azure SQL Database that contains several tables with columns that store personally identifiable information (PII). The security team requires that these columns be identified and labeled as 'Confidential' in the database. You need to implement a solution that automatically classifies these columns based on their names and data patterns. What should you use?

⚠ Common exam trap

A common mix-up: candidates confuse data protection features like DDM or Always Encrypted with data discovery and classification, which is a separate capability for identifying and labeling sensitive data.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

SQL Data Discovery and Classification.

SQL Data Discovery and Classification is the built-in feature in Azure SQL Database that scans for potentially sensitive columns, such as those containing PII, and allows you to apply classification labels like 'Confidential'. It uses pattern matching and column names to provide recommendations, which can be reviewed and applied. This directly meets the requirement to identify and label PII columns.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    SQL Data Discovery and Classification.

    Why this is correct

    SQL Data Discovery and Classification is a feature in Azure SQL Database that scans your database, identifies columns that may contain sensitive data based on names and data patterns, and allows you to apply classification labels such as 'Confidential'. It provides recommendations and can automatically classify columns, meeting the requirement to identify and label PII columns.

  • ✗

    Always Encrypted.

    Why it's wrong here

    Always Encrypted encrypts data at the client side to protect it from high-privileged users, but it does not classify or label columns. It is an encryption feature and does not provide discovery or labeling capabilities. Always Encrypted requires manual configuration of encryption keys and columns, not automatic classification.

  • ✗

    Transparent Data Encryption (TDE).

    Why it's wrong here

    TDE encrypts data at rest and does not classify or label columns. It is a storage-level encryption feature that protects database files and backups. TDE does not scan for PII or apply classification labels; it is unrelated to data discovery and classification requirements.

  • ✗

    Dynamic Data Masking (DDM).

    Why it's wrong here

    DDM masks sensitive data in query results for non-privileged users but does not classify or label columns. It is a data protection feature, not a data discovery or classification tool. DDM does not scan for PII or apply labels; it only obscures data at the presentation layer.

About these practice questions

Courseiva writes every DP-300 question from scratch — 574 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This DP-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-300 exam.