DP-300 Implement a secure environment Practice Question
Your company is migrating on-premises SQL Server databases to Azure SQL Managed Instance. You need to ensure that database backups are encrypted at rest using customer-managed keys stored in Azure Key Vault. You also need to allow the backup service to access the keys. What should you configure?
⚠ Common exam trap
Candidates often confuse Always Encrypted (which protects column data) with TDE (which protects the entire database and backups), leading them to select Option A instead of the correct TDE-based solution.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable Transparent Data Encryption (TDE) with customer-managed keys and grant the managed instance's system-assigned managed identity 'get', 'wrapKey', and 'unwrapKey' permissions on the key vault.
Transparent Data Encryption (TDE) with customer-managed keys (CMK) in Azure SQL Managed Instance encrypts database backups at rest. To allow the Azure backup service to access the key for backup encryption, the managed instance's system-assigned managed identity must be granted 'get', 'wrapKey', and 'unwrapKey' permissions on the Azure Key Vault where the CMK is stored. This ensures that backups are encrypted using the customer-controlled key, meeting the requirement for encryption at rest with customer-managed keys.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use Always Encrypted with column master key stored in Azure Key Vault.
Why it's wrong here
Always Encrypted protects individual columns in transit and at rest from the database engine; it does not encrypt the managed instance's automated backups, which use TDE. It is tempting because Always Encrypted does store its column master key in Azure Key Vault, which would be correct for shielding sensitive columns from administrators.
- ✗
Configure Azure Backup for SQL Server in Azure VM and use Backup Center to manage encryption.
Why it's wrong here
Azure Backup for SQL Server on Azure VMs protects IaaS workloads and cannot manage TDE keys for Azure SQL Managed Instance, whose backups are encrypted by the service. It is tempting because Azure Backup does offer encryption and Backup Center centralises protection, which would fit SQL Server running on virtual machines.
- ✓
Enable Transparent Data Encryption (TDE) with customer-managed keys and grant the managed instance's system-assigned managed identity 'get', 'wrapKey', and 'unwrapKey' permissions on the key vault.
Why this is correct
TDE with customer-managed keys encrypts backups at rest under your Key Vault key, and the system-assigned managed identity must hold get, wrapKey, and unwrapKey so the instance can unwrap the key for backup encryption and decryption operations.
- ✗
Configure server-level firewall rules to allow Azure services to access the server.
Why it's wrong here
Server-level firewall rules govern inbound network connectivity to the managed instance; they grant no permission for the backup service to unwrap keys in Azure Key Vault. It is tempting because firewall rules do control service access, and would be correct for allowing Azure services to reach a logical SQL server.
Go deeper
Related to this question
Learn chapter
Deploying and Configuring Azure SQL Managed Instance
Key term
Azure SQL Managed Instance
Azure SQL Managed Instance is a fully managed cloud database service that gives you nearly all the features of Microsoft SQL Server on your own server, without you having to manage the hardware or operating system.
Key term
Transparent Data Encryption
Transparent Data Encryption is a security feature that automatically encrypts data written to a database and decrypts it when read, without requiring any changes to the application.
About these practice questions
This DP-300 question is part of Courseiva's 574-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DP-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-300 exam.