DP-300 Implement a secure environment Practice Question
A junior developer at your company connects to an Azure SQL Database using the SQL login 'appuser'. You need to grant 'appuser' the ability to read from a table named dbo.Orders in the Sales schema, but nothing else in the database. You also want to follow the principle of least privilege. What should you do?
⚠ Common exam trap
The trap here is reaching for a built-in role such as db_datareader because it is convenient, when it grants read access to every table rather than the one table required.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Grant SELECT on the dbo.Orders table to 'appuser'.
The most granular permission that satisfies the requirement is a table-level GRANT SELECT on dbo.Orders. It gives the developer exactly the read access needed while leaving all other objects inaccessible. Role memberships such as db_datareader and db_owner, and schema-level CONTROL, all grant broader rights than the scenario allows.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Grant SELECT on the dbo.Orders table to 'appuser'.
Why this is correct
A table-level GRANT SELECT gives exactly the read permission required on dbo.Orders and nothing more. It follows least privilege because the user receives no access to other tables, views, or schemas, and it is the most granular standard permission available for this scenario.
- ✗
Add 'appuser' to the db_datareader role.
Why it's wrong here
The db_datareader role grants SELECT on all user tables and views in the database, which is broader than the requirement. The developer would be able to read every table, not just dbo.Orders, so this violates least privilege even though it does provide the needed read access.
- ✗
Add 'appuser' to the db_owner role.
Why it's wrong here
db_owner grants full control over the database, including the ability to drop tables and manage other users. It far exceeds the requirement to read a single table and would allow the developer to alter or destroy data, which directly contradicts the least privilege goal.
- ✗
Grant CONTROL on the Sales schema to 'appuser'.
Why it's wrong here
CONTROL on a schema grants ownership-like permissions over all objects in that schema, including the ability to alter or drop them. The developer only needs to read one table, so granting schema-wide control is excessive and does not meet the least privilege requirement.
Go deeper
Related to this question
Learn chapter
Managing Identity and Access for Azure SQL
Key term
Azure SQL Performance Tuning
Azure SQL Performance Tuning is the process of optimizing the speed and efficiency of queries and database operations in Microsoft Azure SQL Database or SQL Managed Instance to reduce latency and improve throughput.
About these practice questions
One of 574 original DP-300 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This DP-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-300 exam.