DP-300 Implement a secure environment Practice Question
Your company wants to implement transparent data encryption (TDE) for an Azure SQL Database using a customer-managed key stored in Azure Key Vault. Which TWO prerequisites must be met? (Choose two.)
⚠ Common exam trap
A common mix-up: candidates confuse TDE prerequisites with Always Encrypted prerequisites, mistakenly thinking a column master key (Option C) is needed, or they assume the database must be offline (Option E) for key configuration, which is not the case for TDE.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The Azure SQL Server must have a system-assigned managed identity.
Option A is correct because Azure SQL TDE with a customer-managed key (BYOK) requires the logical Azure SQL Server to have a managed identity (system-assigned or user-assigned) that can authenticate to Azure Key Vault; the system-assigned managed identity is the standard prerequisite for granting the server access to the key. Option B is correct because the Key Vault must grant that SQL Server identity the required key permissions — typically get, wrapKey, and unwrapKey — via an access policy (or Azure RBAC role assignment) so the server can wrap and unwrap the TDE protector key. Option C is not required: a column master key belongs to Always Encrypted, not TDE, which uses a database encryption key (DEK) protected by a server-level TDE protector. Option D is incorrect because the Key Vault and SQL Server can be in the same region; there is no requirement that they be in different regions. Option E is incorrect because TDE key configuration does not require taking the database offline; the operation is performed online without database downtime.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The Azure SQL Server must have a system-assigned managed identity.
Why this is correct
A system-assigned managed identity gives the Azure SQL logical server an identity in Microsoft Entra ID, which Key Vault access policies and key wrapping require. Without it, the server cannot authenticate to the vault to unwrap the customer-managed TDE protector.
- ✓
The Key Vault must have an access policy granting necessary permissions to the SQL Server identity.
Why this is correct
Key Vault access policies must grant the SQL server's managed identity get, wrapKey and unwrapKey permissions. This lets the server retrieve and unwrap the customer-managed TDE protector; without it, TDE with customer-managed keys cannot be enabled.
- ✗
The database must contain a column master key.
Why it's wrong here
Column master keys belong to Always Encrypted, which protects individual columns client-side. It is tempting because both features use Azure Key Vault, but TDE encrypts the entire database at rest and requires a Key Vault key, not a column master key.
- ✗
The Key Vault must be in a different region than the SQL Server.
Why it's wrong here
The Key Vault must reside in the same region as the Azure SQL logical server; cross-region vaults are rejected. It is tempting because geo-redundant vaults exist for resilience, but TDE customer-managed key configuration requires regional proximity, not separation.
- ✗
The database must be taken offline during key configuration.
Why it's wrong here
TDE key configuration happens online; the database stays available throughout. It is tempting because key rotation historically implied maintenance windows, but Azure SQL applies the key without downtime, so taking the database offline is unnecessary and disruptive.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
Learn chapter
Deploying and Configuring SQL Server on Azure Virtual Machines
Key term
Azure SQL Performance Tuning
Azure SQL Performance Tuning is the process of optimizing the speed and efficiency of queries and database operations in Microsoft Azure SQL Database or SQL Managed Instance to reduce latency and improve throughput.
Key term
Transparent Data Encryption
Transparent Data Encryption is a security feature that automatically encrypts data written to a database and decrypts it when read, without requiring any changes to the application.
About these practice questions
One of 574 original DP-300 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DP-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-300 exam.