DP-300 Implement a secure environment Practice Question
You manage an Azure SQL Database that contains a table with a column named 'CreditCardNumber' that stores sensitive data. You need to ensure that the data in this column is encrypted at rest and in use, and that only specific application users can decrypt it. You also need to minimize performance impact on queries that do not access this column. What should you implement?
⚠ Common exam trap
The trap here is assuming that Transparent Data Encryption or Dynamic Data Masking provides in-use encryption and granular decryption control, when only Always Encrypted with secure enclaves does.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Always Encrypted with secure enclaves and column master key stored in Azure Key Vault.
Always Encrypted with secure enclaves is designed to protect sensitive data both at rest and in use. It uses column encryption keys and a column master key stored in a key store such as Azure Key Vault. Only clients with access to the column master key can decrypt data. Secure enclaves allow computations on encrypted data without exposing it to the database engine. This approach meets the need for granular access control and minimal performance impact on unrelated queries.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Always Encrypted with secure enclaves and column master key stored in Azure Key Vault.
Why this is correct
Always Encrypted with secure enclaves protects data at rest and in use, and allows rich computations on encrypted data within the enclave. The column master key in Azure Key Vault controls access, so only clients with permission to the key can decrypt. Queries not accessing the encrypted column are unaffected, minimizing performance impact. This meets all requirements: encryption at rest and in use, granular access control, and minimal impact.
- ✗
Dynamic Data Masking on the 'CreditCardNumber' column.
Why it's wrong here
Dynamic Data Masking masks data in query results for non-privileged users but does not encrypt the data at rest or in use. The actual data remains plaintext in the database, and users with sufficient privileges can see it unmasked. It does not prevent database administrators from viewing the data. Thus, it fails to meet the encryption and access control requirements.
- ✗
Row-Level Security (RLS) with a security policy that filters rows based on user identity.
Why it's wrong here
Row-Level Security controls which rows a user can access but does not encrypt data. It operates on plaintext data and does not protect against privileged users or off-line attacks. It also does not provide column-level encryption. Therefore, it does not satisfy the requirement for encryption at rest and in use, nor does it restrict decryption to specific application users.
- ✗
Transparent Data Encryption (TDE) with a customer-managed key in Azure Key Vault.
Why it's wrong here
TDE encrypts the entire database at rest, including backups, but it does not protect data in use from database administrators or users with query access. It also does not allow column-level granularity; all data is decrypted transparently for any authorized connection. Therefore, it does not meet the requirement that only specific application users can decrypt the column, and it does not protect data in use.
Go deeper
Related to this question
Learn chapter
Monitoring Database Performance with Azure Tools
Key term
Azure SQL Performance Tuning
Azure SQL Performance Tuning is the process of optimizing the speed and efficiency of queries and database operations in Microsoft Azure SQL Database or SQL Managed Instance to reduce latency and improve throughput.
About these practice questions
One of 574 original DP-300 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This DP-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-300 exam.