DP-300 Implement a secure environment Practice Question
A developer at your company needs to run ad hoc queries against an Azure SQL Database from a workstation on the corporate network. Security policy forbids storing credentials in the application and forbids any inbound public network access to the database. The workstation already has a Microsoft Entra ID-joined identity. What should you configure to meet these requirements?
⚠ Common exam trap
The trap here is treating a firewall rule as equivalent to removing public access, when an IP rule still leaves the public endpoint reachable.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a contained database user mapped to the Microsoft Entra identity and connect through a private endpoint using Microsoft Entra authentication
Meeting both constraints requires an authentication method that needs no stored secret and a network path that avoids the public endpoint. A contained database user mapped to a Microsoft Entra identity lets the developer sign in with directory credentials, and a private endpoint routes traffic over the private network. Password-based logins and firewall rules that keep the public endpoint reachable fail the policy.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable the Allow Azure services and resources to access this server firewall rule and connect over the public endpoint
Why it's wrong here
This firewall rule opens the server to a broad range of Azure-originated traffic and leaves the public endpoint in place, which violates the prohibition on inbound public network access. It also does not address authentication, so the developer would still need credentials. It fails on both the network and credential constraints.
- ✗
Create a SQL login with a strong password and store the password in the connection string on the workstation
Why it's wrong here
A SQL login requires a password, and placing it in a connection string on the workstation is precisely the credential-storage practice the policy prohibits. It also does nothing to remove the public endpoint if the firewall still permits the workstation. This approach fails the no-stored-credential requirement.
- ✓
Create a contained database user mapped to the Microsoft Entra identity and connect through a private endpoint using Microsoft Entra authentication
Why this is correct
A contained database user mapped to a Microsoft Entra identity lets the developer authenticate with their existing directory credentials, so no password is stored anywhere. Pairing that with a private endpoint keeps all traffic on the private network and removes public exposure. This combination satisfies both the no-stored-credential and no-public-access constraints without extra secrets.
- ✗
Issue the developer a shared SQL login and restrict it with an IP-based firewall rule for the corporate egress address
Why it's wrong here
A shared SQL login still relies on a password that must be conveyed and stored, and an IP firewall rule keeps the public endpoint reachable from that address, so public exposure remains. Sharing an identity also destroys individual accountability. This option fails the no-public-access and no-stored-credential requirements.
Go deeper
Related to this question
Learn chapter
Managing Identity and Access for Azure SQL
Key term
Azure SQL Performance Tuning
Azure SQL Performance Tuning is the process of optimizing the speed and efficiency of queries and database operations in Microsoft Azure SQL Database or SQL Managed Instance to reduce latency and improve throughput.
About these practice questions
Courseiva writes every DP-300 question from scratch — 574 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This DP-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-300 exam.