DP-300 Implement a secure environment Practice Question
Your company has an Azure SQL Database that stores sensitive customer data. You need to ensure that data is encrypted at rest and in transit. The database is currently using Transparent Data Encryption (TDE) with service-managed keys. Compliance requirements now mandate that you use customer-managed keys stored in Azure Key Vault. Additionally, all connections must use encrypted connections. What should you do?
⚠ Common exam trap
Watch out — candidates often confuse Always Encrypted with TDE, thinking column-level encryption satisfies the 'at rest' requirement for the entire database, or they assume that setting 'Minimum TLS version' alone ensures all connections are encrypted, when in fact 'Encrypted connection' must be explicitly set to 'Required' to reject unencrypted connections.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure the Azure SQL Server to use a customer-managed key from Azure Key Vault for TDE and set 'Encrypted connection' to 'Required' on the server.
It directly addresses both requirements: using a customer-managed key from Azure Key Vault for TDE (which replaces the service-managed key) and enforcing encrypted connections by setting 'Encrypted connection' to 'Required' on the Azure SQL Server. This configuration ensures data at rest is encrypted with a key you control, and all client connections must use TLS encryption, meeting compliance mandates without requiring a new database or data migration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a new Azure SQL Database with TDE enabled using a customer-managed key from Key Vault. Migrate data using SQL Server Management Studio (SSMS) with 'Encrypt connection' enabled.
Why it's wrong here
Creating a new database with a customer-managed TDE key satisfies at-rest encryption, but SSMS 'Encrypt connection' only secures that migration session, not ongoing connections. It is tempting because it achieves the CMK requirement, yet the stem demands server-level enforcement of encrypted connections for all clients.
- ✓
Configure the Azure SQL Server to use a customer-managed key from Azure Key Vault for TDE and set 'Encrypted connection' to 'Required' on the server.
Why this is correct
Configuring a customer-managed key in Azure Key Vault for TDE satisfies the compliance mandate for customer-controlled encryption at rest, while setting Encrypted connection to Required enforces encryption in transit for all connections to the Azure SQL server.
- ✗
Enable Transparent Data Encryption (TDE) with service-managed keys and set 'Minimum TLS version' to 1.2.
Why it's wrong here
Service-managed TDE keys already encrypt at rest, so this changes nothing about the customer-managed key mandate; setting minimum TLS 1.2 does address transit encryption. It is tempting because TLS enforcement is genuinely required, but the at-rest requirement for Key Vault-held keys remains unmet.
- ✗
Implement Always Encrypted with keys stored in Azure Key Vault and set 'Encrypted connection' to 'Required' on the server.
Why it's wrong here
Always Encrypted protects specific columns client-side and does not replace TDE's at-rest encryption of the whole database with a customer-managed key. It is tempting because it uses Key Vault and enforces encrypted connections, its real purpose being column-level protection, but the stem requires CMK-backed TDE.
Go deeper
Related to this question
Learn chapter
Securing Data at Rest and in Transit
Key term
Transparent Data Encryption
Transparent Data Encryption is a security feature that automatically encrypts data written to a database and decrypts it when read, without requiring any changes to the application.
Key term
Azure SQL Performance Tuning
Azure SQL Performance Tuning is the process of optimizing the speed and efficiency of queries and database operations in Microsoft Azure SQL Database or SQL Managed Instance to reduce latency and improve throughput.
About these practice questions
Courseiva writes every DP-300 question from scratch — 574 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DP-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-300 exam.