Courseiva

DP-900 Practice Question: Identify considerations for relational data on Azure

A retail company uses Azure SQL Database for its inventory system. The database stores sensitive customer information that must be encrypted at rest to comply with data protection regulations. Which feature should they enable?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Transparent Data Encryption (TDE)

Transparent Data Encryption (TDE) is the correct choice because it encrypts Azure SQL Database data at rest at the page level, protecting the database files, backups, and log files without requiring application changes. This directly satisfies the regulatory requirement for encryption at rest of sensitive customer information. Dynamic Data Masking only obfuscates data in query results and does not encrypt stored data, so it does not meet the at-rest encryption requirement. Always Encrypted protects data in use and at rest but is designed for client-side encryption of specific columns and requires application changes, making it unnecessary here. Azure Information Protection is a data classification and labeling service for documents and emails, not a database at-rest encryption feature.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Dynamic Data Masking

    Why it's wrong here

    Dynamic Data Masking obscures column values in query results for non-privileged users, but leaves the underlying data stored unencrypted on disk, so it cannot satisfy an encryption-at-rest requirement. It is tempting because it protects sensitive customer data from casual viewing, and would be the right choice when the goal is limiting data exposure in query output rather than encrypting stored data.

  • ✗

    Always Encrypted

    Why it's wrong here

    Always Encrypted protects individual columns from database administrators by keeping keys client-side, but it does not satisfy encryption at rest for the whole database. It is tempting because it encrypts sensitive customer data, yet it targets in-use and in-motion column protection; Transparent Data Encryption is the feature that encrypts data at rest.

  • ✗

    Azure Information Protection

    Why it's wrong here

    Azure Information Protection classifies and labels documents and emails, not database storage engines, so it cannot encrypt Azure SQL Database data at rest. It is tempting because it applies encryption to sensitive data, but that protection targets files and messages in Microsoft 365 workloads, making it the right choice for labelling and protecting shared documents rather than transparent database encryption.

  • ✓

    Transparent Data Encryption (TDE)

    Why this is correct

    Transparent Data Encryption encrypts Azure SQL Database data and backups at rest at the page level, using a database encryption key protected by a key vault. This satisfies the regulatory requirement for encryption at rest without application changes.

About these practice questions

This DP-900 question is part of Courseiva's 851-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DP-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-900 exam.