DP-900 Practice Question: Identify considerations for relational data on Azure
A company stores customer data in an Azure SQL Database. To comply with data residency requirements, they need to ensure that all customer data remains within a specific Azure region. Which feature should they use?
⚠ Common exam trap
DP-900 often tests the confusion between encryption, masking, and residency controls — candidates pick TDE or masking because they sound like 'data protection,' missing that only Azure Policy enforces location.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use Azure Policy to restrict resource creation to allowed regions
Azure Policy can enforce that resources are only created in approved Azure regions, which directly satisfies data residency requirements by preventing deployment of the Azure SQL Database (or any resource) outside the permitted geography. This is the governance control designed for exactly this compliance scenario.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Use Azure Policy to restrict resource creation to allowed regions
Why this is correct
Azure Policy can enforce data residency by applying a policy definition to deny or audit the creation of Azure SQL Database resources outside an approved region. You can target the resource types Microsoft.Sql/servers and Microsoft.Sql/servers/databases, and include parameters for allowed locations so both server and database must be in the required geography. The Deny effect blocks any non-compliant deployment before it happens, while Audit logs violations, making this a governance and compliance control rather than a data-protection feature.
- ✗
Enable geo-replication
Why it's wrong here
Geo-replication copies data continuously to a secondary database in a different Azure region for failover and read-scale scenarios. While the primary database stays in the source region, the secondary replica is a full, live copy stored in another data center, which directly contradicts a data-residency requirement that restricts storage to a specific country or region. The feature is a high-availability solution, not a residency control, so enabling it would create unapproved copies outside the allowed boundary.
- ✗
Configure dynamic data masking
Why it's wrong here
Dynamic data masking is a database-level security feature that limits sensitive data exposure by applying masking rules to query results for non-privileged users, such as showing only the last four digits of a credit card number. It works entirely at the application or query layer and never moves, copies, or relocates the underlying database files. Therefore, it is unrelated to data residency and cannot prevent data from being stored in an unauthorized Azure region.
- ✗
Enable transparent data encryption (TDE)
Why it's wrong here
Transparent data encryption (TDE) performs real-time I/O encryption and decryption of the database's data and log files, using a database encryption key that is protected by a server certificate or an asymmetric key stored in Azure Key Vault. This protects confidentiality at rest against theft of physical disks, but it does not control or alter the geographic location where the database is stored. The encrypted database remains entirely within the region where it was deployed, so TDE provides security but not residency enforcement.
Go deeper
Related to this question
Learn chapter
Azure Database for PostgreSQL
Key term
Azure SQL Database
Azure SQL Database is a fully managed relational database-as-a-service (DBaaS) in Microsoft Azure, based on the SQL Server engine, that handles scaling, backups, patching, and high availability automatically.
Key term
Data
Data is raw, unprocessed information, like numbers, words, or measurements, that can be stored, processed, and analyzed by computers.
About these practice questions
This DP-900 question is part of Courseiva's 851-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This DP-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-900 exam.