DP-300 Implement a secure environment Practice Question
You manage an Azure SQL Database named InventoryDB. The security team requires that all data in the database be encrypted at rest using a key that your organization controls and can revoke. You need to implement this requirement with minimal administrative overhead. What should you do?
⚠ Common exam trap
Many candidates confuse encryption at rest with column-level encryption or masking, or assuming that service-managed keys provide organizational control.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable Transparent Data Encryption (TDE) with a customer-managed key stored in Azure Key Vault.
Transparent Data Encryption with a customer-managed key in Azure Key Vault provides encryption at rest while giving the organization control over the key, including the ability to revoke it. This meets the requirement for organizational control and revocation. Service-managed keys do not offer that control, and Always Encrypted and dynamic data masking address different security concerns. TDE with customer-managed keys is the appropriate solution for encrypting all data at rest with minimal administrative overhead.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure Always Encrypted with column encryption keys stored in Azure Key Vault.
Why it's wrong here
Always Encrypted protects data in use and at rest for specific columns, but it requires application changes and does not encrypt the entire database at rest. The scenario asks for all data to be encrypted at rest, which is the role of TDE. Always Encrypted is for column-level protection and does not meet the blanket encryption requirement with minimal overhead.
- ✗
Implement dynamic data masking on all sensitive columns.
Why it's wrong here
Dynamic data masking obscures data in query results but does not encrypt data at rest. It is a presentation-layer security feature and does not satisfy the requirement for encryption with a revocable key controlled by the organization. This option addresses a different security need and leaves data unencrypted on disk.
- ✓
Enable Transparent Data Encryption (TDE) with a customer-managed key stored in Azure Key Vault.
Why this is correct
TDE with a customer-managed key in Azure Key Vault allows your organization to control and revoke the encryption key. This satisfies the requirement for data encrypted at rest with organizational control. It is the standard method for achieving customer-managed encryption in Azure SQL Database, and it integrates with Key Vault for key management and revocation.
- ✗
Enable Transparent Data Encryption (TDE) with a service-managed key.
Why it's wrong here
Service-managed keys are controlled by Microsoft and cannot be revoked by your organization. The requirement is for a key that your organization controls and can revoke. While TDE with service-managed keys encrypts data at rest, it does not provide the control or revocation capability specified. This option fails to meet the key control requirement.
Go deeper
Related to this question
Learn chapter
Deploying and Configuring Azure SQL Managed Instance
Key term
Transparent Data Encryption
Transparent Data Encryption is a security feature that automatically encrypts data written to a database and decrypts it when read, without requiring any changes to the application.
Key term
Azure SQL Performance Tuning
Azure SQL Performance Tuning is the process of optimizing the speed and efficiency of queries and database operations in Microsoft Azure SQL Database or SQL Managed Instance to reduce latency and improve throughput.
About these practice questions
This DP-300 question is part of Courseiva's 574-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This DP-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-300 exam.