You have an Azure SQL database that contains a table named Customer. Customer contains the columns shown in the following table. You apply a masking rule as shown in the following table. Which users can view the email addresses of the customers?
A.
Server administrators and all users who are granted the UNMASK permission to the Customer_Email column only.
B.
All users who are granted the UNMASK permission to the Customer_Email column only.
C.
Server administrators only.
D.
Server administrators and all users who are granted the SELECT permission to the Customer_Email column only.
Suggested Answer:B🗳️
Grant the UNMASK permission to a user to enable them to retrieve unmasked data from the columns for which masking is defined. Reference: https://docs.microsoft.com/en-us/sql/relational-databases/security/dynamic-data-masking
As for me, the answer is C Server administrators only, because in this particular case Users excluded = None, so no one was granted the UNMASK permission.
Agree with @MsIrene.
"SQL users excluded from masking - A set of SQL users or Azure AD identities that get unmasked data in the SQL query results. Users with administrator privileges are always excluded from masking, and see the original data without any mask."
https://docs.microsoft.com/en-us/azure/azure-sql/database/dynamic-data-masking-overview
A seems to be the correct answer.. Refer to Dynamic data masking policy > SQL users excluded from masking of the page below, which mentions "Users with administrator privileges are always excluded from masking, and see the original data without any mask." . Hands-on would clear any further confusion.
https://docs.microsoft.com/en-us/azure/azure-sql/database/dynamic-data-masking-overview
Correct, answer is A.
Users with administrator privileges always have access to the original unmasked data.
https://docs.microsoft.com/en-us/azure/azure-sql/database/dynamic-data-masking-configure-portal
Agree-"However this permission is globally applied at the database level, meaning that if a user has this permission, they have the ability to read the actual data in any column for which they have SELECT permission"
Correct Answer is A.
Type the SQL users or Azure Active Directory (Azure AD) identities that should be excluded from masking, and have access to the unmasked sensitive data. This should be a semicolon-separated list of users. Users with administrator privileges always have access to the original unmasked data.
For this scenario, the answer is C since by default Server Administrator is excluded from masking and there are no indicated users in the "users excluded" which in case if there is then the values are visible to those people.
correct answer is C
When grant unmask it allows to expose all of the mask columns from a table. Given the option A, it states at the end that it will only unmask the "email" column only.
SQL users excluded from masking - A set of SQL users or Azure AD identities that get unmasked data in the SQL query results. Users with administrator privileges are always excluded from masking, and see the original data without any mask.
https://docs.microsoft.com/en-us/azure/azure-sql/database/dynamic-data-masking-overview#dynamic-data-masking-policy
upvoted 4 times
...
This section is not available anymore. Please use the main Exam Page.DP-200 Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
MsIrene
Highly Voted 4 years, 1 month agoyassine70
3 years, 8 months agodataeng1102
Highly Voted 4 years, 2 months agoDevendra00023
4 years, 2 months agoDMQA
4 years, 1 month ago111222333
4 years agoHinzzz
Most Recent 3 years, 11 months agoVishalTile
3 years, 12 months agobs_2021
3 years, 11 months agolapomidoro
4 years agopsal2020
3 years, 11 months agoAmy007
4 years agocadio30
4 years, 1 month agocadio30
4 years agocadio30
4 years agoNamishBansal
4 years, 1 month agoMily94
4 years, 1 month agosamkslee
4 years, 1 month ago