Microsoft Azure Security Engineer Associate AZ-500 Practice Question
You manage an Azure SQL Database that has a dynamic data masking rule applied to the Salary column of the dbo.Employees table. Members of the Analytics database role must run ad-hoc read-only queries that display the real Salary values, but they must not be able to modify data, alter the table schema, or change masking policies. Following the principle of least privilege, which single permission should you grant to the Analytics role?
Grant the ALTER ANY MASK permission on the database to the Analytics role.
Grant the CONTROL permission on dbo.Employees to the Analytics role.
Grant the UNMASK permission on the database to the Analytics role.
Grant the UNMASK permission on OBJECT::dbo.Employees to the Analytics role.
Granting the UNMASK permission on the dbo.Employees table lets the Analytics role bypass masking only for that specific table, exposing the true Salary values while conferring no data-modification or schema-alteration rights. Granting UNMASK at the database scope would reveal unmasked data in every masked column across the database, which is broader than required. ALTER ANY MASK would allow users to create, alter, or drop masking rules, and CONTROL on the table would provide full DDL and DML access-both exceed least-privilege.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is dynamic data masking in Azure SQL Database?
Open an interactive chat with Bash
What is the UNMASK permission in Azure SQL Database?
Open an interactive chat with Bash
What is the principle of least privilege in Azure role-based permissions?
Open an interactive chat with Bash
Microsoft Azure Security Engineer Associate AZ-500
Secure compute, storage, and databases
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .