Courseiva

DP-300 Implement a secure environment Practice Question

A junior developer at your company connects to an Azure SQL Database using the SQL login 'appuser'. You need to grant 'appuser' the ability to read from a table named dbo.Orders in the Sales schema, but nothing else in the database. You also want to follow the principle of least privilege. What should you do?

⚠ Common exam trap

The trap here is reaching for a built-in role such as db_datareader because it is convenient, when it grants read access to every table rather than the one table required.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Grant SELECT on the dbo.Orders table to 'appuser'.

The most granular permission that satisfies the requirement is a table-level GRANT SELECT on dbo.Orders. It gives the developer exactly the read access needed while leaving all other objects inaccessible. Role memberships such as db_datareader and db_owner, and schema-level CONTROL, all grant broader rights than the scenario allows.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Grant SELECT on the dbo.Orders table to 'appuser'.

    Why this is correct

    A table-level GRANT SELECT gives exactly the read permission required on dbo.Orders and nothing more. It follows least privilege because the user receives no access to other tables, views, or schemas, and it is the most granular standard permission available for this scenario.

  • ✗

    Add 'appuser' to the db_datareader role.

    Why it's wrong here

    The db_datareader role grants SELECT on all user tables and views in the database, which is broader than the requirement. The developer would be able to read every table, not just dbo.Orders, so this violates least privilege even though it does provide the needed read access.

  • ✗

    Add 'appuser' to the db_owner role.

    Why it's wrong here

    db_owner grants full control over the database, including the ability to drop tables and manage other users. It far exceeds the requirement to read a single table and would allow the developer to alter or destroy data, which directly contradicts the least privilege goal.

  • ✗

    Grant CONTROL on the Sales schema to 'appuser'.

    Why it's wrong here

    CONTROL on a schema grants ownership-like permissions over all objects in that schema, including the ability to alter or drop them. The developer only needs to read one table, so granting schema-wide control is excessive and does not meet the least privilege requirement.

About these practice questions

One of 574 original DP-300 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This DP-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-300 exam.