Courseiva

DP-300 Implement a secure environment Practice Question

You manage an Azure SQL Database named InventoryDB. The security team requires that all data in the database be encrypted at rest using a key that your organization controls and can revoke. You need to implement this requirement with minimal administrative overhead. What should you do?

⚠ Common exam trap

Many candidates confuse encryption at rest with column-level encryption or masking, or assuming that service-managed keys provide organizational control.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable Transparent Data Encryption (TDE) with a customer-managed key stored in Azure Key Vault.

Transparent Data Encryption with a customer-managed key in Azure Key Vault provides encryption at rest while giving the organization control over the key, including the ability to revoke it. This meets the requirement for organizational control and revocation. Service-managed keys do not offer that control, and Always Encrypted and dynamic data masking address different security concerns. TDE with customer-managed keys is the appropriate solution for encrypting all data at rest with minimal administrative overhead.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure Always Encrypted with column encryption keys stored in Azure Key Vault.

    Why it's wrong here

    Always Encrypted protects data in use and at rest for specific columns, but it requires application changes and does not encrypt the entire database at rest. The scenario asks for all data to be encrypted at rest, which is the role of TDE. Always Encrypted is for column-level protection and does not meet the blanket encryption requirement with minimal overhead.

  • ✗

    Implement dynamic data masking on all sensitive columns.

    Why it's wrong here

    Dynamic data masking obscures data in query results but does not encrypt data at rest. It is a presentation-layer security feature and does not satisfy the requirement for encryption with a revocable key controlled by the organization. This option addresses a different security need and leaves data unencrypted on disk.

  • ✓

    Enable Transparent Data Encryption (TDE) with a customer-managed key stored in Azure Key Vault.

    Why this is correct

    TDE with a customer-managed key in Azure Key Vault allows your organization to control and revoke the encryption key. This satisfies the requirement for data encrypted at rest with organizational control. It is the standard method for achieving customer-managed encryption in Azure SQL Database, and it integrates with Key Vault for key management and revocation.

  • ✗

    Enable Transparent Data Encryption (TDE) with a service-managed key.

    Why it's wrong here

    Service-managed keys are controlled by Microsoft and cannot be revoked by your organization. The requirement is for a key that your organization controls and can revoke. While TDE with service-managed keys encrypts data at rest, it does not provide the control or revocation capability specified. This option fails to meet the key control requirement.

Go deeper

Related to this question

About these practice questions

This DP-300 question is part of Courseiva's 574-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This DP-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-300 exam.