Courseiva

DP-300 Implement a secure environment Practice Question

Your company has an Azure SQL Database that stores sensitive customer data. You need to ensure that data is encrypted at rest and in transit. The database is currently using Transparent Data Encryption (TDE) with service-managed keys. Compliance requirements now mandate that you use customer-managed keys stored in Azure Key Vault. Additionally, all connections must use encrypted connections. What should you do?

⚠ Common exam trap

Watch out — candidates often confuse Always Encrypted with TDE, thinking column-level encryption satisfies the 'at rest' requirement for the entire database, or they assume that setting 'Minimum TLS version' alone ensures all connections are encrypted, when in fact 'Encrypted connection' must be explicitly set to 'Required' to reject unencrypted connections.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure the Azure SQL Server to use a customer-managed key from Azure Key Vault for TDE and set 'Encrypted connection' to 'Required' on the server.

It directly addresses both requirements: using a customer-managed key from Azure Key Vault for TDE (which replaces the service-managed key) and enforcing encrypted connections by setting 'Encrypted connection' to 'Required' on the Azure SQL Server. This configuration ensures data at rest is encrypted with a key you control, and all client connections must use TLS encryption, meeting compliance mandates without requiring a new database or data migration.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a new Azure SQL Database with TDE enabled using a customer-managed key from Key Vault. Migrate data using SQL Server Management Studio (SSMS) with 'Encrypt connection' enabled.

    Why it's wrong here

    Creating a new database with a customer-managed TDE key satisfies at-rest encryption, but SSMS 'Encrypt connection' only secures that migration session, not ongoing connections. It is tempting because it achieves the CMK requirement, yet the stem demands server-level enforcement of encrypted connections for all clients.

  • ✓

    Configure the Azure SQL Server to use a customer-managed key from Azure Key Vault for TDE and set 'Encrypted connection' to 'Required' on the server.

    Why this is correct

    Configuring a customer-managed key in Azure Key Vault for TDE satisfies the compliance mandate for customer-controlled encryption at rest, while setting Encrypted connection to Required enforces encryption in transit for all connections to the Azure SQL server.

  • ✗

    Enable Transparent Data Encryption (TDE) with service-managed keys and set 'Minimum TLS version' to 1.2.

    Why it's wrong here

    Service-managed TDE keys already encrypt at rest, so this changes nothing about the customer-managed key mandate; setting minimum TLS 1.2 does address transit encryption. It is tempting because TLS enforcement is genuinely required, but the at-rest requirement for Key Vault-held keys remains unmet.

  • ✗

    Implement Always Encrypted with keys stored in Azure Key Vault and set 'Encrypted connection' to 'Required' on the server.

    Why it's wrong here

    Always Encrypted protects specific columns client-side and does not replace TDE's at-rest encryption of the whole database with a customer-managed key. It is tempting because it uses Key Vault and enforces encrypted connections, its real purpose being column-level protection, but the stem requires CMK-backed TDE.

Go deeper

Related to this question

About these practice questions

Courseiva writes every DP-300 question from scratch — 574 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DP-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-300 exam.