Courseiva

DP-300 Implement a secure environment Practice Question

Your company wants to implement transparent data encryption (TDE) for an Azure SQL Database using a customer-managed key stored in Azure Key Vault. Which TWO prerequisites must be met? (Choose two.)

⚠ Common exam trap

A common mix-up: candidates confuse TDE prerequisites with Always Encrypted prerequisites, mistakenly thinking a column master key (Option C) is needed, or they assume the database must be offline (Option E) for key configuration, which is not the case for TDE.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The Azure SQL Server must have a system-assigned managed identity.

Option A is correct because Azure SQL TDE with a customer-managed key (BYOK) requires the logical Azure SQL Server to have a managed identity (system-assigned or user-assigned) that can authenticate to Azure Key Vault; the system-assigned managed identity is the standard prerequisite for granting the server access to the key. Option B is correct because the Key Vault must grant that SQL Server identity the required key permissions — typically get, wrapKey, and unwrapKey — via an access policy (or Azure RBAC role assignment) so the server can wrap and unwrap the TDE protector key. Option C is not required: a column master key belongs to Always Encrypted, not TDE, which uses a database encryption key (DEK) protected by a server-level TDE protector. Option D is incorrect because the Key Vault and SQL Server can be in the same region; there is no requirement that they be in different regions. Option E is incorrect because TDE key configuration does not require taking the database offline; the operation is performed online without database downtime.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The Azure SQL Server must have a system-assigned managed identity.

    Why this is correct

    A system-assigned managed identity gives the Azure SQL logical server an identity in Microsoft Entra ID, which Key Vault access policies and key wrapping require. Without it, the server cannot authenticate to the vault to unwrap the customer-managed TDE protector.

  • ✓

    The Key Vault must have an access policy granting necessary permissions to the SQL Server identity.

    Why this is correct

    Key Vault access policies must grant the SQL server's managed identity get, wrapKey and unwrapKey permissions. This lets the server retrieve and unwrap the customer-managed TDE protector; without it, TDE with customer-managed keys cannot be enabled.

  • ✗

    The database must contain a column master key.

    Why it's wrong here

    Column master keys belong to Always Encrypted, which protects individual columns client-side. It is tempting because both features use Azure Key Vault, but TDE encrypts the entire database at rest and requires a Key Vault key, not a column master key.

  • ✗

    The Key Vault must be in a different region than the SQL Server.

    Why it's wrong here

    The Key Vault must reside in the same region as the Azure SQL logical server; cross-region vaults are rejected. It is tempting because geo-redundant vaults exist for resilience, but TDE customer-managed key configuration requires regional proximity, not separation.

  • ✗

    The database must be taken offline during key configuration.

    Why it's wrong here

    TDE key configuration happens online; the database stays available throughout. It is tempting because key rotation historically implied maintenance windows, but Azure SQL applies the key without downtime, so taking the database offline is unnecessary and disruptive.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

Go deeper

Related to this question

About these practice questions

One of 574 original DP-300 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DP-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-300 exam.