Courseiva

DP-300 Implement a secure environment Practice Question

You manage an Azure SQL Database that contains a table with a column named CreditCardNumber. The security team requires that this column be encrypted so that even database administrators cannot view the plaintext values. The application that inserts and queries data must continue to work with minimal changes, and the encryption keys must be stored in Azure Key Vault. What should you implement?

⚠ Common exam trap

The trap here is assuming that TDE or dynamic data masking protects data from DBAs; only Always Encrypted keeps plaintext away from the database engine.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Always Encrypted with column master key in Azure Key Vault and column encryption key for the CreditCardNumber column.

Always Encrypted ensures that sensitive data is never revealed to the database engine, protecting it from DBAs. The column master key stored in Azure Key Vault satisfies the key management requirement. Applications need only enable Always Encrypted in the client driver and use parameterized queries, which is a minimal change compared to other encryption methods.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Dynamic data masking on the CreditCardNumber column with a masking rule that shows only the last four digits.

    Why it's wrong here

    Dynamic data masking hides data from non-privileged users but does not encrypt the data at rest, and privileged users can still see the unmasked values. It does not prevent database administrators from viewing plaintext. The requirement explicitly states that even DBAs should not see plaintext, which masking cannot guarantee.

  • ✗

    Row-level security (RLS) with a security policy that filters rows based on user identity.

    Why it's wrong here

    Row-level security controls which rows a user can access but does not encrypt column data. It does not prevent a DBA from viewing the CreditCardNumber column if they have access to the row. The requirement is about protecting the column values themselves, not restricting row access.

  • ✗

    Transparent Data Encryption (TDE) with a customer-managed key in Azure Key Vault.

    Why it's wrong here

    TDE encrypts the entire database at rest, but database administrators with access to the database can still query and see plaintext data. It does not prevent DBAs from viewing sensitive column values. The requirement is to protect specific column data from privileged users, which TDE does not achieve.

  • ✓

    Always Encrypted with column master key in Azure Key Vault and column encryption key for the CreditCardNumber column.

    Why this is correct

    Always Encrypted is designed to protect sensitive data from high-privileged users like DBAs. The client driver encrypts and decrypts data, so the database engine never sees plaintext. Storing the column master key in Azure Key Vault meets the key storage requirement. The application requires minimal changes: it needs to use a supported client driver with Always Encrypted enabled and connection string adjustments.

About these practice questions

Courseiva writes every DP-300 question from scratch — 574 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This DP-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-300 exam.