Courseiva

SC-100 Design security solutions for infrastructure Practice Question

Your organization uses Azure SQL Database and needs to protect sensitive data from being exported by unauthorized users. You must implement a solution that prevents users from copying data to clipboard or taking screenshots of query results, while allowing legitimate business operations. What should you implement?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure a session policy in Microsoft Defender for Cloud Apps to block clipboard and screenshot actions.

The correct option is D: configuring a session policy in Microsoft Defender for Cloud Apps to block clipboard and screenshot actions. Defender for Cloud Apps Conditional Access App Control uses a session policy to proxy the session and apply controls such as blocking copy/paste to the clipboard and preventing screenshots, which directly addresses the requirement while still permitting legitimate query operations. Option A is incorrect because Azure Information Protection labels classify and protect data at rest or in documents, not interactive query result sessions. Option B is incorrect because Dynamic Data Masking only obscures column values in query output and does not prevent copying or screenshotting. Option C is incorrect because Auditing and threat detection only log and alert on suspicious activity; they do not block clipboard or screenshot actions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Apply Azure Information Protection labels to the database.

    Why it's wrong here

    Azure Information Protection (AIP) labels, including SQL Information Protection classifications in Azure SQL Database, attach sensitivity metadata and can enforce encryption/document protections, but they do not operate at the interactive session level. A label alone cannot intercept client-side actions such as clipboard copy/paste or screenshot capture in SSMS or the Azure Portal. AIP is a classification and data-identity control, not a data-loss-prevention (DLP) enforcement point for live query results. To block exfiltration, you must broker the user's client behavior, which labels cannot do.

  • ✗

    Use Dynamic Data Masking to obscure sensitive columns.

    Why it's wrong here

    Dynamic Data Masking (DDM) automatically obfuscates sensitive columns for unprivileged users at the database engine level, but it only changes the values returned to the client. If a masked user runs a query, they receive masked data and are free to copy, paste, or screenshot that output because DDM has no insight into, nor control over, the user's client device or browser. Moreover, DDM can be bypassed by users with EXECUTE permission on unmasking functions or via inference techniques like side-channel attacks. The correct control must apply policy at the client session boundary, not just transform query results.

  • ✗

    Enable Azure SQL Database Auditing and threat detection.

    Why it's wrong here

    Azure SQL Database Auditing and Microsoft Defender for SQL threat detection are essential detective controls: auditing writes an immutable log of queries and events to a storage account or Log Analytics workspace, while threat detection alerts on anomalies like SQL injection or brute-force attacks. However, both operate after the action occurs or at best provide near-real-time alerts; they do not interrupt a user's session or block a clipboard/screenshot operation mid-flight. They answer 'who did what' but not 'stop that now.' A Defender for Cloud Apps session policy, by contrast, is a preventive control that actively denies the forbidden client action at the moment it is attempted.

  • ✓

    Configure a session policy in Microsoft Defender for Cloud Apps to block clipboard and screenshot actions.

    Why this is correct

    Configuring a session policy in Microsoft Defender for Cloud Apps (MDA) is a preventive, real-time DLP control that uses a reverse-proxy architecture to sit between the user and Azure SQL Database. When a user accesses the database through a supported web portal or app, the session policy can apply conditional access and enforce behavioral controls such as blocking clipboard operations (copy, cut, paste) and prohibiting screenshot capture, thereby preventing data exfiltration at the client session level. This goes beyond traditional database permissions and masking because MDA inspects and restricts the user's interactive environment in real time. To be effective, you target the specific app (e.g., Azure Portal or SQL Query Editor) and define policy conditions and actions for sensitive data.

About these practice questions

One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.