Courseiva

DP-300 Implement a secure environment Practice Question

You manage an Azure SQL Database that contains a table with sensitive columns. You need to implement Dynamic Data Masking so that users in the 'Reporting' database role see masked values, while users in the 'DataEntry' role see unmasked values. You have created the masking rules. Which two actions should you perform to meet the requirement? (Choose two.)

⚠ Common exam trap

The trap here is assuming that masking rules themselves can be targeted to specific roles, when in fact masking is controlled by the UNMASK permission and applies to all users who lack it.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Ensure the 'Reporting' role does not have the UNMASK permission.

Dynamic Data Masking is enforced through the UNMASK permission. Users without UNMASK see masked data; users with UNMASK see the original values. To allow the DataEntry role to see unmasked data, you grant UNMASK to that role. To ensure the Reporting role sees masked data, you must verify that the role (and its members) does not have UNMASK. These two actions together satisfy the requirement without altering the masking rules.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Alter the masking rules to use the 'default()' function for the sensitive columns.

    Why it's wrong here

    The default() function is one of the masking functions, but changing the masking function does not control which users see masked data. The requirement is about role-based visibility, which is governed by the UNMASK permission. Using default() would still mask the data for all users without UNMASK and would not exempt the DataEntry role, so it does not solve the problem.

  • ✓

    Ensure the 'Reporting' role does not have the UNMASK permission.

    Why this is correct

    By default, users without UNMASK see masked data. To ensure the Reporting role sees masked values, you must confirm that the role does not possess UNMASK, either directly or through role membership. If the role or its members had UNMASK, they would see the unmasked data, defeating the purpose. Thus, verifying and, if necessary, revoking UNMASK from the Reporting role is required.

  • ✓

    Grant the UNMASK permission to the 'DataEntry' role.

    Why this is correct

    The UNMASK permission allows a user or role to see unmasked data even when a masking rule applies. By granting UNMASK to the DataEntry role, members of that role will see the original values. This is the correct way to exempt specific users from masking without altering the masking rules themselves, and it follows the least privilege principle by limiting the exemption to that role.

  • ✗

    Create a separate database user for each member of the 'Reporting' role.

    Why it's wrong here

    Dynamic Data Masking operates based on permissions, not on individual user accounts. Creating separate users for each member of the Reporting role does not affect masking behavior and adds unnecessary administrative overhead. The masking rules apply uniformly to all users without UNMASK, so individual accounts are not needed to enforce the masking for that role.

  • ✗

    Enable auditing on the database to track who views masked data.

    Why it's wrong here

    Auditing records access to data but does not change whether data is masked or unmasked. It is a monitoring feature, not an access control feature. While auditing can be useful for compliance, it does not grant the DataEntry role the ability to see unmasked values or ensure the Reporting role sees masked values. Therefore, it does not meet the stated requirement.

About these practice questions

This DP-300 question is part of Courseiva's 574-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This DP-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-300 exam.