Q: 4
Your company has on-premises Microsoft SQL Server databases.
The company plans to move the databases to Azure.
You need to recommend a secure architecture for the databases that will minimize operational
requirements for patching and protect sensitive data by using dynamic data masking. The solution
must minimize costs.
What should you include in the recommendation?
Options
Discussion
C tbh, had something like this in a mock. Azure SQL Database covers patching and data masking with less effort or cost than the other options.
C or A. If there were cross-database transactions or other server-level requirements, Azure SQL Managed Instance (A) might be needed, but with basic needs like DDM and patching and minimum cost, pretty sure C is the right call. Let me know if anyone hit an edge case needing MI on this.
C fits best since Azure SQL Database is a PaaS option, so Microsoft takes care of most patching and updates. Dynamic Data Masking is built in, and costs are lower compared to Managed Instance or spinning up VMs. I’ve seen similar advice in the official guide. Not 100% sure if there’s any hidden gotcha, but C seems to tick all the boxes-anyone think Managed Instance could be better for some edge cases?
Be respectful. No spam.