Courseiva

Microsoft Azure Database Administrator Associate DP-300 (DP-300) — Questions 526–574

574 questions total · 8pages · All types, answers revealed

Page 7

Page 8 of 8

526
MCQhard

You are reviewing an ARM template for creating a new Azure SQL Database. The template uses the above JSON to create a database named 'db2' from 'db1'. The source database 'db1' is currently in a failed state due to a storage issue. What will be the result of deploying this template?

A.The deployment will fail because db1 is not in a recoverable state.
B.It will create an empty database because the source is not accessible.
C.It will delete db1 and create db2 as a replacement.
D.It will create a new database by recovering db1 to its last known good state.
AnswerA

A point-in-time restore or database copy requires the source database to be online and recoverable. Because db1 is in a failed state from a storage issue, the control-plane operation cannot read its backups, so the ARM deployment returns an error rather than creating db2.

Why this answer

The ARM template creates a new database by copying from a source database. Azure SQL Database requires the source database to be in an online and healthy state to perform a copy operation. Since db1 is in a failed state due to a storage issue, it is not accessible for copying, so the deployment will fail.

Exam trap

The trap here is that candidates may confuse a database copy with a point-in-time restore, assuming that a failed source can still be used to create a new database via recovery, but the copy operation explicitly requires an online source.

How to eliminate wrong answers

Option B is wrong because Azure SQL Database does not create an empty database when the source is inaccessible; the copy operation requires a valid, online source. Option C is wrong because the ARM template does not include a delete operation; it only creates a new database from a source, and Azure SQL Database does not automatically delete the source during a copy. Option D is wrong because the template specifies a copy operation, not a point-in-time restore; recovering to a last known good state would require a different ARM template or a restore command, not a database copy.

527
MCQmedium

Refer to the exhibit. You run the above PowerShell command to set the Transparent Data Encryption (TDE) protector for an Azure SQL Database server. What is the result?

A.The command fails because the service principal does not have permissions to the key vault.
B.Transparent Data Encryption is disabled.
C.The TDE protector for the database "mydb" is updated.
D.The server’s TDE protector is changed to a customer-managed key from Azure Key Vault.
AnswerD

The cmdlet sets a customer-managed key as the server's TDE protector, satisfying the requirement to move encryption key custody from Microsoft-managed to your own Azure Key Vault. The protector must reside in the same region as the server, and the key's permissions grant the server access for wrap and unwrap operations.

Why this answer

The PowerShell command Set-AzSqlServerTransparentDataEncryptionProtector with -Type AzureKeyVault changes the server-level TDE protector to a customer-managed key stored in Azure Key Vault. This is the documented cmdlet for configuring Bring Your Own Key (BYOK) TDE at the Azure SQL logical server level, and the result is that the server's TDE protector is now the specified Key Vault key.

Exam trap

The trap is confusing server-level and database-level TDE operations — candidates may pick the database-scoped answer because the question mentions a database name, but the cmdlet and the TDE protector are server-scoped objects.

How to eliminate wrong answers

Option A is wrong because the question asks for the result of the command, not a failure scenario — while permissions are required, the cmdlet is designed to succeed when the service principal has been granted wrapKey/unwrapKey/get permissions on the key vault, and the question does not indicate a permissions problem. Option B is wrong because setting a TDE protector does not disable TDE — TDE remains enabled and is now backed by a customer-managed key rather than the service-managed key. Option C is wrong because the cmdlet operates at the server level (Set-AzSqlServerTransparentDataEncryptionProtector), not the database level; the TDE protector is a server-scoped object, and databases inherit it.

528
MCQmedium

You are troubleshooting a performance degradation on an Azure SQL Database. You notice that the database is hitting the maximum DTU limit frequently. Which action should you take first to reduce DTU consumption?

A.Increase the log rate limit
B.Scale up the database to a higher service tier
C.Use Query Performance Insight to identify and optimize top resource-consuming queries
D.Rebuild all indexes in the database
AnswerC

Query Performance Insight surfaces the top CPU, duration and DTU-consuming queries, letting you tune indexes or rewrite statements to cut DTU usage. Scaling the tier would mask the problem rather than reduce consumption, so identifying the offending queries comes first.

Why this answer

The first step to reduce DTU consumption is to identify the queries causing the high resource usage using Query Performance Insight. This tool provides detailed metrics on top resource-consuming queries, enabling targeted optimization. Scaling up or rebuilding indexes without identifying the root cause may not address the underlying inefficiency and could increase costs unnecessarily.

Exam trap

DP-300 often tests the tendency to jump to scaling as a first response, rather than diagnosing and optimizing the workload.

How to eliminate wrong answers

Option A is wrong because increasing the log rate limit does not reduce DTU consumption; it may allow more transactions but does not address the cause of high DTU usage. Option B is wrong because scaling up to a higher service tier increases available DTUs but does not reduce consumption; it only provides more resources, which may mask the problem and increase cost. Option D is wrong because rebuilding all indexes is a broad action that may improve performance but is not the first step; it could be unnecessary and disruptive without first identifying the problematic queries.

529
MCQeasy

You are optimizing an Azure SQL Database that runs a heavy reporting workload. The database uses the General Purpose tier. You notice that many queries are scanning large tables. What is the best first action to improve performance?

A.Partition the large tables by date.
B.Analyze the missing index recommendations from Query Store.
C.Scale up to Business Critical tier.
D.Implement columnstore indexes on all large tables.
AnswerB

Query Store captures missing index recommendations from actual workload history, letting you add indexes that eliminate the large table scans. This directly targets the scan bottleneck and is the cheapest first action, unlike scaling the General Purpose tier or rewriting queries blindly.

Why this answer

Query Store's missing index recommendations directly identify indexes that, if created, would likely improve the performance of the observed scanning queries. This is the most targeted, low-risk first action because it is based on actual workload data and addresses the root cause (missing indexes causing scans) without changing the service tier or making structural changes. It is also the cheapest and fastest to implement.

Exam trap

The trap is assuming that scaling up (more hardware) or partitioning (structural change) is the best first step, when the exam expects you to identify the least invasive, data-driven action — analyzing existing recommendations before making costly changes.

How to eliminate wrong answers

Option A is wrong because partitioning large tables by date helps with partition elimination and manageability but does not address the fundamental issue of missing indexes causing full table scans on reporting queries. Option C is wrong because scaling up to Business Critical increases cost significantly and does not fix the underlying query inefficiency — it just throws more hardware at the problem, which is not the best first action. Option D is wrong because implementing columnstore indexes on all large tables is a broad, potentially disruptive change that may not suit all workloads (e.g., OLTP-style queries) and should be evaluated after analyzing specific query patterns, not applied blindly.

530
MCQeasy

You are designing a secure environment for Azure SQL Database. Which authentication method provides the strongest security and supports multi-factor authentication?

A.Certificate-based authentication
B.Azure Active Directory authentication
C.SQL authentication with strong passwords
D.Windows authentication
AnswerB

Microsoft Entra ID authentication centralises identity in a directory that enforces multi-factor authentication, conditional access and passwordless methods, satisfying the stem's demand for the strongest security. Unlike SQL logins, credentials are not stored in the database, and tokens are issued per user, enabling auditing and revocation.

Why this answer

Azure Active Directory (Azure AD) authentication is the recommended method for Azure SQL Database because it supports multi-factor authentication (MFA), conditional access policies, and identity-driven security. It eliminates the need for password management and leverages Azure AD's built-in security features, providing the strongest security posture for cloud-native environments.

Exam trap

The trap here is that candidates often assume Windows authentication (Option D) is available in Azure SQL Database because of their on-premises experience, but Azure SQL Database does not support Windows authentication—only Azure AD authentication provides integrated identity management and MFA.

How to eliminate wrong answers

Option A is wrong because certificate-based authentication is not a native authentication method for Azure SQL Database; it can be used only as part of Azure AD authentication or for specific scenarios like service principals, not as a standalone method. Option C is wrong because SQL authentication with strong passwords still relies on a static credential stored in the database, making it vulnerable to brute-force attacks and lacking MFA support. Option D is wrong because Windows authentication is not supported for Azure SQL Database; it is only available for on-premises SQL Server or Azure SQL Managed Instance when integrated with Active Directory.

531
MCQmedium

You are a database administrator for a company that runs a SaaS application on Azure SQL Database. The application's workload is unpredictable, with rapid bursts of activity that last only a few minutes. You need to ensure that the database can handle these bursts without manual intervention, while minimizing cost during idle periods. What should you do?

A.Configure the database to use the Hyperscale service tier with a fixed number of vCores.
B.Enable the serverless compute tier for the database.
C.Create a read scale-out replica and route all write operations to the primary replica.
D.Implement elastic database pool with multiple databases sharing resources.
AnswerB

The serverless compute tier automatically scales compute resources based on workload demand and pauses the database during inactive periods, billing only for storage. This directly addresses unpredictable bursts by scaling up during activity and scaling down or pausing when idle, minimizing cost. It requires no manual intervention and is ideal for intermittent, unpredictable workloads.

Why this answer

The serverless compute tier is specifically designed for single databases with unpredictable or intermittent usage. It automatically scales compute based on demand and pauses during inactivity, which directly addresses the need to handle bursts without manual intervention while minimizing cost. Other options either require manual scaling or are optimized for different scenarios such as large databases or read offloading.

Exam trap

The trap here is assuming that any auto-scaling feature, such as read scale-out or elastic pools, will handle unpredictable compute bursts for a single database.

532
MCQhard

Your company is migrating on-premises SQL Server databases to Azure SQL Managed Instance. You need to ensure that database backups are encrypted at rest using customer-managed keys stored in Azure Key Vault. You also need to allow the backup service to access the keys. What should you configure?

A.Use Always Encrypted with column master key stored in Azure Key Vault.
B.Configure Azure Backup for SQL Server in Azure VM and use Backup Center to manage encryption.
C.Enable Transparent Data Encryption (TDE) with customer-managed keys and grant the managed instance's system-assigned managed identity 'get', 'wrapKey', and 'unwrapKey' permissions on the key vault.
D.Configure server-level firewall rules to allow Azure services to access the server.
AnswerC

TDE with customer-managed keys encrypts backups at rest under your Key Vault key, and the system-assigned managed identity must hold get, wrapKey, and unwrapKey so the instance can unwrap the key for backup encryption and decryption operations.

Why this answer

Transparent Data Encryption (TDE) with customer-managed keys (CMK) in Azure SQL Managed Instance encrypts database backups at rest. To allow the Azure backup service to access the key for backup encryption, the managed instance's system-assigned managed identity must be granted 'get', 'wrapKey', and 'unwrapKey' permissions on the Azure Key Vault where the CMK is stored. This ensures that backups are encrypted using the customer-controlled key, meeting the requirement for encryption at rest with customer-managed keys.

Exam trap

The trap here is that candidates confuse Always Encrypted (which protects column data) with TDE (which protects the entire database and backups), leading them to select Option A instead of the correct TDE-based solution.

How to eliminate wrong answers

Option A is wrong because Always Encrypted protects column data in transit and at rest on the client side, not database backups; it does not encrypt backups or involve the backup service. Option B is wrong because Azure Backup for SQL Server in Azure VM is for SQL Server on Azure VMs, not Azure SQL Managed Instance, and Backup Center is a management interface, not a mechanism to encrypt backups with customer-managed keys. Option D is wrong because server-level firewall rules control network access, not encryption of backups; they do not address key management or backup encryption requirements.

533
MCQeasy

You are responsible for an Azure SQL Database that hosts a reporting application. Users complain that queries are slow during business hours. You run a query against sys.dm_db_resource_stats and see that the average CPU percentage is consistently above 90%, while other metrics are low. You need to identify the queries contributing most to CPU usage. What should you use?

A.Query Store's Top Resource Consuming Queries report.
B.Extended Events session capturing sql_statement_completed events.
C.Azure SQL Database Intelligent Insights.
D.Dynamic management view sys.dm_exec_query_stats.
AnswerA

Query Store captures query execution statistics, including CPU time, duration, and execution count. The Top Resource Consuming Queries report in the Azure portal or via Query Store catalog views ranks queries by resource consumption, making it ideal for identifying which queries are driving high CPU usage. This directly addresses the need to pinpoint CPU-intensive queries.

Why this answer

Query Store's Top Resource Consuming Queries report aggregates query performance data and ranks queries by resource usage, including CPU time. It retains historical data, so even if plans are evicted, the information remains. This makes it the best tool to identify which queries are responsible for sustained high CPU in the database.

Exam trap

The trap here is relying on sys.dm_exec_query_stats, which only shows currently cached plans and lacks historical context, potentially missing the actual CPU-consuming queries.

534
MCQeasy

You manage an Azure SQL Database named InventoryDB. The security team requires that all data in the database be encrypted at rest using a key that your organization controls and can revoke. You need to implement this requirement with minimal administrative overhead. What should you do?

A.Configure Always Encrypted with column encryption keys stored in Azure Key Vault.
B.Implement dynamic data masking on all sensitive columns.
C.Enable Transparent Data Encryption (TDE) with a customer-managed key stored in Azure Key Vault.
D.Enable Transparent Data Encryption (TDE) with a service-managed key.
AnswerC

TDE with a customer-managed key in Azure Key Vault allows your organization to control and revoke the encryption key. This satisfies the requirement for data encrypted at rest with organizational control. It is the standard method for achieving customer-managed encryption in Azure SQL Database, and it integrates with Key Vault for key management and revocation.

Why this answer

Transparent Data Encryption with a customer-managed key in Azure Key Vault provides encryption at rest while giving the organization control over the key, including the ability to revoke it. This meets the requirement for organizational control and revocation. Service-managed keys do not offer that control, and Always Encrypted and dynamic data masking address different security concerns.

TDE with customer-managed keys is the appropriate solution for encrypting all data at rest with minimal administrative overhead.

Exam trap

The trap here is confusing encryption at rest with column-level encryption or masking, or assuming that service-managed keys provide organizational control.

535
MCQmedium

You are deploying a new application on Azure SQL Database. The application requires that all connections use a specific login, 'AppUser', with the least privileges necessary. The login should only be able to execute stored procedures in the 'Sales' schema and should not have direct access to underlying tables. What should you do?

A.Grant the SELECT permission on the 'Sales' schema to 'AppUser'.
B.Add 'AppUser' to the db_datareader role.
C.Create a database role, grant EXECUTE on the 'Sales' schema to the role, and add 'AppUser' to the role.
D.Grant the EXECUTE permission on each stored procedure individually to 'AppUser'.
AnswerC

Schema-scoped EXECUTE permission on the Sales schema lets AppUser run stored procedures without SELECT rights on base tables, satisfying least privilege. Ownership chaining means the procedures access tables under the schema owner's permissions, so no direct table grants are needed.

Why this answer

Creating a database role, granting EXECUTE on the 'Sales' schema to that role, and adding 'AppUser' to the role follows the principle of least privilege. This allows 'AppUser' to execute stored procedures in the Sales schema without granting direct table access, because stored procedures execute with ownership chaining or elevated permissions. This is the most maintainable and secure approach.

Exam trap

DP-300 often tests the misconception that granting EXECUTE on a schema automatically grants table access; candidates must understand ownership chaining and that schema-level EXECUTE is sufficient for stored procedure execution without direct table permissions.

How to eliminate wrong answers

Option A is wrong because granting SELECT on the 'Sales' schema gives direct read access to all tables, violating the requirement that the user should not have direct access to underlying tables. Option B is wrong because adding 'AppUser' to the db_datareader role grants SELECT on all user tables in the database, which is far too broad and violates least privilege. Option D is wrong because granting EXECUTE on each stored procedure individually is tedious, error-prone, and does not scale; schema-level grants are preferred for maintainability.

536
MCQmedium

You manage an Azure SQL Database that is experiencing higher than expected DTU consumption. You need to identify which queries are consuming the most resources. Which dynamic management view should you query?

A.Query sys.dm_exec_requests
B.Query sys.dm_os_wait_stats
C.Query sys.dm_exec_query_stats
D.Query sys.dm_db_resource_stats
AnswerC

sys.dm_exec_query_stats aggregates execution counts, CPU time and logical reads per cached plan, so ordering by total resource consumption reveals the heaviest queries. This satisfies the requirement to identify which queries drive the elevated DTU usage on the Azure SQL Database.

Why this answer

sys.dm_exec_query_stats returns aggregate performance statistics for cached query plans, including total worker time, logical reads, and execution counts. This makes it the correct DMV to identify which queries consume the most resources, as it directly attributes resource usage to individual query statements. By ordering by total_worker_time or total_logical_reads, you can pinpoint the top resource-consuming queries.

Exam trap

DP-300 often tests the difference between DMVs that show current activity (sys.dm_exec_requests) versus those that show historical aggregates (sys.dm_exec_query_stats), and candidates may confuse instance-level wait stats with query-level resource consumption.

How to eliminate wrong answers

Option A is wrong because sys.dm_exec_requests shows currently executing requests, not historical aggregate resource consumption, so it cannot identify the top consumers over time. Option B is wrong because sys.dm_os_wait_stats provides wait statistics at the instance level, indicating what resources are being waited on, but not which queries are responsible. Option D is wrong because sys.dm_db_resource_stats shows resource usage for the database as a whole (CPU, IO, memory) over time, not per-query breakdowns.

537
MCQeasy

You are the administrator for an Azure SQL Database. The security team requires that all authentication to the database use Microsoft Entra ID (formerly Azure AD) and that multi-factor authentication (MFA) be enforced. You need to configure the database to meet this requirement. What should you do first?

A.Enable Microsoft Entra ID authentication in the Azure SQL Database firewall settings.
B.Configure a Conditional Access policy to require MFA for all users.
C.Set a Microsoft Entra ID admin for the Azure SQL logical server.
D.Create a contained database user for each Microsoft Entra ID user.
AnswerC

To enable Microsoft Entra ID authentication for Azure SQL Database, you must first assign a Microsoft Entra ID admin at the server level. This admin can then create contained database users mapped to Microsoft Entra identities. Once set, clients can authenticate using Microsoft Entra ID, and MFA can be enforced through Conditional Access policies. This is the foundational step for Entra ID authentication.

Why this answer

The first step to enable Microsoft Entra ID authentication for Azure SQL Database is to set a Microsoft Entra ID admin on the logical server. This admin can then manage Entra ID identities and create contained database users. MFA enforcement is achieved through Conditional Access policies in Microsoft Entra ID, but those policies only apply once Entra ID authentication is enabled.

Therefore, setting the Entra ID admin is the prerequisite.

Exam trap

The trap here is jumping to Conditional Access policies or contained users without first establishing the Microsoft Entra ID admin, which is the prerequisite for Entra ID authentication.

538
MCQmedium

You are migrating an on-premises SQL Server 2019 database to Azure SQL Managed Instance. The database uses cross-database queries and SQL Server Agent jobs. You need to ensure that the migration is as seamless as possible and that these features continue to work after migration. What should you do first?

A.Create a new Azure SQL Managed Instance with the same configuration as the on-premises server.
B.Enable cross-database queries on the Azure SQL Managed Instance after migration.
C.Run the Data Migration Assistant (DMA) to assess compatibility and identify unsupported features.
D.Use the Azure Database Migration Service (DMS) to perform an online migration.
AnswerC

Data Migration Assistant (DMA) is the recommended tool to assess on-premises SQL Server databases for migration to Azure SQL Managed Instance. It identifies compatibility issues, unsupported features, and provides recommendations. For a database using cross-database queries and SQL Server Agent, DMA will verify that these features are supported in Azure SQL Managed Instance and highlight any necessary changes before migration, ensuring a smoother process.

Why this answer

Before migrating to Azure SQL Managed Instance, you should run the Data Migration Assistant (DMA) to assess the source database for compatibility. DMA identifies features like cross-database queries and SQL Server Agent that are supported in Azure SQL Managed Instance and flags any issues. This assessment ensures a seamless migration by allowing you to address problems beforehand.

Other steps are either part of the migration process or post-migration tasks, not the initial action.

Exam trap

The trap here is skipping assessment and directly using a migration tool, which can lead to failures due to undetected compatibility issues.

539
MCQmedium

You are managing an Azure SQL Database that uses the vCore purchasing model. You need to configure an alert that fires when the database's CPU usage exceeds 80% for 10 minutes. You want to minimize administrative effort. What should you do?

A.Configure a diagnostic setting to stream logs to Log Analytics and create a log alert.
B.Create an alert rule in Azure Monitor based on the cpu_percent metric.
C.Enable automatic tuning and configure it to send email notifications.
D.Create a SQL Agent job that checks sys.dm_db_resource_stats and sends an email.
AnswerB

Azure Monitor provides built-in metrics for Azure SQL Database, including cpu_percent. You can create an alert rule that triggers when the average cpu_percent exceeds 80% over a 10-minute window. This is the most direct and least administrative effort because it uses platform metrics and the Azure Monitor alerting framework, with no need to write custom queries or deploy additional components.

Why this answer

Azure Monitor metric alerts can directly monitor the cpu_percent metric for Azure SQL Database. You can set a threshold of 80% over a 10-minute aggregation window. This requires minimal configuration and no custom code.

Other options either do not support the requirement (automatic tuning), are not available (SQL Agent), or involve more effort (Log Analytics). Therefore, creating an Azure Monitor alert rule is the correct and most efficient solution.

Exam trap

The trap here is overcomplicating the solution by using Log Analytics or custom jobs, when Azure Monitor metric alerts provide a built-in, low-effort mechanism.

540
Multi-Selectmedium

You are optimizing an Azure SQL Database that uses the General Purpose service tier. You observe that the database is experiencing high wait times due to PAGEIOLATCH_SH waits. You need to reduce these waits. Which two actions should you perform? (Choose two.)

Select 2 answers
A.Increase the database's max size.
B.Enable Query Store and force the last known good plan.
C.Add appropriate indexes to reduce the number of pages read.
D.Enable read scale-out and redirect reporting queries to the secondary replica.
E.Scale up the database to a higher service tier or compute size.
AnswersC, E

PAGEIOLATCH_SH waits occur when queries read data pages from storage. Adding appropriate indexes, such as covering indexes, can reduce the number of pages that must be read to satisfy a query, thereby decreasing physical IO and the associated waits. This is a targeted optimization that addresses the query workload itself. It is especially effective when queries perform scans that can be converted to seeks with the right indexes.

Why this answer

PAGEIOLATCH_SH waits indicate that queries are waiting for data pages to be read from storage. To reduce these waits, you can either increase the IO throughput and reduce latency by scaling up the database to a higher service tier or compute size, or reduce the number of pages read by adding appropriate indexes. Both actions address the underlying cause: insufficient IO performance or excessive IO demand.

Increasing max size or enabling read scale-out do not directly improve primary IO for read-write workloads.

Exam trap

The trap here is thinking that read scale-out or Query Store plan forcing will reduce IO waits, when the real solutions are increasing IO capacity or reducing IO demand through indexing.

541
MCQhard

You are a database administrator for a multinational corporation that uses Azure SQL Managed Instance. The instance is part of a failover group for disaster recovery. You need to automate the process of testing the failover group by performing a planned failover to the secondary region and then failing back. The test must be performed monthly during a maintenance window. The automation must ensure that the failover group is in a healthy state before and after the test and must log the results to a table. What should you do?

A.Use Elastic Database Jobs to run T-SQL that initiates failover and logs results.
B.Create an Azure Automation runbook with PowerShell that uses the Az.Sql module to perform failover and log to a table.
C.Use Azure Data Factory to execute a stored procedure that performs failover.
D.Create a SQL Agent job with T-SQL that performs the planned failover using ALTER AVAILABILITY GROUP and logs the results to a table.
AnswerB

Correct. Azure Automation runbooks can be scheduled to run monthly, use the Az.Sql module to perform planned failover and failback, and log results to a table. Although not entirely self-contained, it is the only viable option.

Why this answer

Azure Automation runbooks with PowerShell and the Az.Sql module can programmatically invoke failover group operations (e.g., Invoke-AzSqlDatabaseFailoverGroup), check health state, and log results to a table (e.g., via AzTable or SQL). Automation runbooks support schedules (monthly maintenance window), managed identities for authentication, and full scripting control to verify the failover group is healthy before and after. This is the canonical Azure-native approach for orchestrating cross-region failover tests.

Exam trap

DP-300 often tests the distinction between control-plane operations (Azure PowerShell/CLI/REST) and data-plane T-SQL — candidates pick SQL Agent or Elastic Jobs because they think failover can be done in T-SQL, but failover group operations require Azure control-plane APIs.

How to eliminate wrong answers

Option A is wrong because Elastic Database Jobs are designed to run T-SQL across multiple databases (e.g., sharded workloads) and do not have native cmdlets to initiate Azure SQL Managed Instance failover group operations — failover is a control-plane operation, not a T-SQL operation. Option C is wrong because Azure Data Factory is an ETL/orchestration service for data movement and transformation; it can run stored procedures but cannot perform control-plane failover group operations and is not designed for this automation. Option D is wrong because SQL Agent jobs run T-SQL inside the instance, and while ALTER AVAILABILITY GROUP exists for availability groups, failover group failover in Azure SQL MI is performed via Azure control-plane APIs (PowerShell/CLI/REST), not T-SQL — SQL Agent also cannot easily authenticate to the Azure control plane.

542
MCQmedium

You administer an Azure SQL Database that must run a nightly index maintenance job. The job must execute T-SQL against the database, and you want to minimize administrative overhead by avoiding external schedulers or custom code. You create an elastic job agent and a target group that includes the database. What should you do next to define the T-SQL command that the job runs?

A.Create an Azure Automation runbook that connects to the database and runs the T-SQL.
B.Create a stored procedure in the master database of the logical server.
C.Create a SQL Server Agent job on the logical server that hosts the database.
D.Create a job step in the elastic job that contains the T-SQL script.
AnswerD

A job step is the unit that holds the T-SQL to be executed by the elastic job agent. After creating the job, you add one or more job steps, each with a command and a target group. This directly meets the requirement without external schedulers, because the agent handles scheduling and execution against the target database.

Why this answer

Elastic jobs consist of a job, one or more job steps, and a target group. The job step holds the T-SQL command that the agent executes against the target databases. Creating a job step is the necessary next action to define the maintenance script, while the other options either use unsupported features or add unnecessary external components.

Exam trap

The trap here is assuming that SQL Server Agent is available in Azure SQL Database, when it is not; scheduling T-SQL natively requires elastic jobs or an external orchestrator.

543
MCQhard

You have an Azure SQL Database in the General Purpose tier. You notice that the log write throughput is consistently above the service tier limit, causing transaction throttling. You need to resolve this without moving to Business Critical. What should you do?

A.Increase the max log size using ALTER DATABASE.
B.Batch transactions and reduce log writes.
C.Enable accelerated database recovery to reduce log I/O.
D.Move to Business Critical tier.
AnswerB

Log write throughput is capped by the General Purpose tier, so throttling stems from excessive log generation. Batching transactions and reducing log writes lowers the log rate itself, resolving throttling without the cost of moving to Business Critical.

Why this answer

Batching transactions reduces the number of log write operations, lowering the log write throughput below the service tier limit and avoiding throttling. Option A is incorrect because increasing the max log size does not affect the log write rate; it only provides more storage. Option C is incorrect because accelerated database recovery (ADR) improves recovery time and may reduce log I/O for crash recovery, but it does not directly reduce the sustained log write throughput from transaction processing.

Option D is incorrect because the requirement explicitly states not to move to Business Critical.

Exam trap

Candidates may think that increasing log size or enabling ADR will solve throttling, but only reducing log writes (via batching or minimally logged operations) addresses the throughput limit.

544
MCQhard

You manage a SQL Server 2019 availability group on Azure Virtual Machines. The availability group has three replicas: one primary and two synchronous secondary replicas in the same region. A fourth asynchronous replica is in a different Azure region for disaster recovery. During a planned maintenance window, you need to perform a manual failover to one of the synchronous secondary replicas without data loss. Which Transact-SQL command should you run on the target secondary replica?

A.ALTER AVAILABILITY GROUP [AG1] MODIFY REPLICA ON 'SQL2' WITH (FAILOVER_MODE = MANUAL);
B.ALTER AVAILABILITY GROUP [AG1] FAILOVER;
C.ALTER AVAILABILITY GROUP [AG1] SET (ROLE = SECONDARY);
D.ALTER AVAILABILITY GROUP [AG1] FORCE_FAILOVER_ALLOW_DATA_LOSS;
AnswerB

The ALTER AVAILABILITY GROUP ... FAILOVER command performs a manual failover without data loss when the target secondary is synchronized. It is the correct command to use on the secondary replica that you want to become the new primary, ensuring no data loss because the secondary is synchronous and up to date. This meets the requirement for a planned failover without data loss.

Why this answer

To perform a planned manual failover without data loss in an availability group, you run ALTER AVAILABILITY GROUP ... FAILOVER on the target secondary replica. This command requires the secondary to be synchronized with the primary and ensures no data loss.

The FORCE_FAILOVER_ALLOW_DATA_LOSS option is for unplanned failover with potential data loss, while the other options are configuration commands that do not initiate a failover.

Exam trap

The trap here is confusing the command for a planned failover with the one for a forced failover that allows data loss.

545
MCQmedium

Refer to the exhibit. An Azure SQL Database is receiving Intelligent Insights degradation alerts. Which action should be taken first?

A.Increase the maximum storage size
B.Change the service tier to BusinessCritical
C.Scale up to Standard S3 (100 DTU)
D.Implement automatic tuning recommendations
AnswerD

Intelligent Insights identifies regressions caused by query plan changes, and automatic tuning can apply the corrective plan or index fix without manual intervention. Implementing recommendations first restores performance directly, satisfying the requirement to resolve the degradation before deeper investigation.

Why this answer

Intelligent Insights is an Azure SQL Database feature that uses built-in intelligence to detect and diagnose performance degradation, and it surfaces root cause analysis along with recommended actions. The first and most appropriate response is to apply the automatic tuning recommendations it provides, because Intelligent Insights alerts are diagnostic in nature and typically point to issues like missing indexes, parameter sniffing, or plan regressions that automatic tuning can resolve without changing the service tier or storage. Scaling resources or changing tiers does not address the underlying query-level cause and may be unnecessary or costly.

Exam trap

DP-300 often tests the misconception that any performance alert should be resolved by scaling up resources, when in fact Intelligent Insights alerts are designed to be addressed first through automatic tuning recommendations that target the root cause.

How to eliminate wrong answers

Option A is wrong because increasing maximum storage size only affects the database's capacity ceiling and does nothing to resolve performance degradation caused by query plan or index issues that Intelligent Insights reports. Option B is wrong because moving to Business Critical changes the underlying hardware and adds local SSD and read replicas, which is a costly architectural change that does not target the specific root cause identified by Intelligent Insights and is not a first-step remediation. Option C is wrong because scaling up to Standard S3 (100 DTU) increases compute resources but does not fix the query-level problems Intelligent Insights diagnoses, and it may not even be the correct tier or size for the workload.

546
MCQmedium

You are configuring Azure SQL Database for an e-commerce application that experiences variable traffic. You need to ensure that the database can automatically scale resources based on demand without manual intervention. The solution must also support scaling to zero compute when not in use to save costs. Which Azure SQL Database offering should you use?

A.Azure SQL Database serverless.
B.Azure SQL Database elastic pool.
C.Azure SQL Database Hyperscale.
D.Azure SQL Database Business Critical tier.
AnswerA

Azure SQL Database serverless automatically scales compute based on workload demand and can pause, scaling compute to zero during inactivity, billing only for storage while paused. This satisfies both constraints: no manual intervention for variable e-commerce traffic, and cost savings through zero-compute scaling when the database is unused.

Why this answer

Azure SQL Database serverless is the correct choice because it automatically scales compute resources based on demand and supports pausing the database when idle, effectively scaling to zero compute to save costs. This aligns perfectly with the requirements of variable traffic and cost optimization without manual intervention.

Exam trap

The trap here is that candidates may confuse the auto-scaling of serverless with the resource pooling of elastic pools, or assume Hyperscale's high performance includes cost-saving idle scaling, but only serverless offers the specific 'scale to zero' capability.

How to eliminate wrong answers

Option B is wrong because Azure SQL Database elastic pool provides resource sharing among multiple databases but does not support scaling to zero compute; it maintains a minimum resource allocation. Option C is wrong because Azure SQL Database Hyperscale is designed for large databases with high storage and throughput needs, not for automatic scaling to zero compute or cost savings through pausing. Option D is wrong because the Business Critical tier offers high availability and performance with fixed compute resources, lacking the ability to scale to zero or pause automatically.

547
MCQmedium

A company uses Azure SQL Database for a critical application. They need to automate the process of exporting a database to a storage account every night, ensuring the export is consistent. The solution must minimize administrative overhead. What should they use?

A.Create an Azure Automation runbook that uses the Export-AzureRmSqlDatabase cmdlet and schedule it to run nightly.
B.Create an Elastic Database Job that runs a T-SQL script to export the database.
C.Deploy an Azure Data Factory pipeline with a Copy activity to export the database.
D.Use an Azure Logic App with the SQL Server connector to export the database.
AnswerA

This is correct because Azure Automation provides a native scheduler for PowerShell runbooks, and Export-AzureRmSqlDatabase creates a BACPAC file (a transactionally consistent backup) in Azure Storage. The cmdlet orchestrates the export through the Azure SQL Database management plane, ensuring a consistent snapshot of the live database. Running nightly via schedule meets the backup requirement without manual intervention, making it the simplest and most reliable option for automated database export.

Why this answer

Azure Automation runbooks can execute PowerShell cmdlets like Export-AzureRmSqlDatabase (or the newer Export-AzSqlDatabase) to perform a consistent export of an Azure SQL Database to a storage account. By scheduling the runbook to run nightly, you automate the export with minimal administrative overhead, as the export operation uses database snapshots to ensure consistency without requiring complex orchestration.

Exam trap

The trap here is that candidates often overcomplicate the solution by choosing Azure Data Factory or Logic Apps, thinking they need a full ETL tool, when a simple scheduled PowerShell runbook is the most direct and low-overhead method for a consistent database export to storage.

How to eliminate wrong answers

Option B is wrong because Elastic Database Jobs are designed for executing T-SQL scripts across multiple databases (e.g., schema changes, index maintenance), not for exporting a database to a storage account; they lack native support for storage account interactions. Option C is wrong because Azure Data Factory pipelines with Copy activity can export data, but they require building a full pipeline with linked services and datasets, which introduces more administrative overhead than a simple scheduled runbook for a straightforward export task. Option D is wrong because Azure Logic Apps with the SQL Server connector can perform operations like querying or inserting data, but they do not support exporting an entire database to a storage account as a consistent backup; the connector lacks the necessary export functionality.

548
MCQeasy

Your organization requires that all changes to sensitive data in an Azure SQL Database be logged for compliance. You need to capture who changed what data and when, and store the logs in a Log Analytics workspace for analysis. What should you configure?

A.Enable change tracking on the database.
B.Enable Microsoft Defender for Cloud on the server.
C.Configure server-level auditing to send logs to a Log Analytics workspace.
D.Enable Transparent Data Encryption (TDE) with customer-managed keys.
AnswerC

Server-level auditing in Azure SQL Database captures the identity, statement and timestamp of every data modification and can stream audit records directly to a Log Analytics workspace, satisfying the requirement to record who changed what and when for compliance analysis.

Why this answer

Server-level auditing in Azure SQL Database can be configured to send audit logs directly to a Log Analytics workspace, capturing detailed information about data changes including who made the change, what was changed, and when. This meets the compliance requirement for logging sensitive data changes and enables analysis using Log Analytics queries.

Exam trap

The trap here is that candidates confuse change tracking (which only detects row changes) with auditing (which captures who, what, and when), or they think security tools like Defender for Cloud provide granular data change logging.

How to eliminate wrong answers

Option A is wrong because change tracking only identifies which rows changed and the fact of a change, but does not capture who made the change or the old/new values, and it does not send logs to Log Analytics. Option B is wrong because Microsoft Defender for Cloud provides security alerts and vulnerability assessments, not granular data change auditing with user identity and timestamp logging. Option D is wrong because Transparent Data Encryption (TDE) with customer-managed keys encrypts data at rest but does not log data changes or provide audit trails.

549
MCQmedium

You manage an Azure SQL Database named SalesDB in the East US region, Business Critical tier. The database has a long-term retention policy that stores weekly full backups in a geo-redundant storage account. During a compliance audit, you need to prove that you can recover SalesDB to a point in time in the event of a complete East US regional outage. You must perform a geo-restore to the West US region. What is the maximum retention period for point-in-time restore that you can expect when performing this geo-restore?

A.The most recent geo-replicated backup, which is typically within one hour of the current time.
B.Up to 35 days, because geo-restore uses the same retention period as standard point-in-time restore.
C.Up to 14 days, because the long-term retention policy retains weekly full backups that can be used for geo-restore.
D.Up to 7 days, because geo-replicated backups are retained for 7 days by default.
AnswerA

Geo-restore uses the latest geo-replicated backup, which is typically no older than one hour. You cannot choose an arbitrary point in time; you restore to the most recent available geo-replicated backup. This is a key limitation for disaster recovery when using geo-restore for Azure SQL Database, as opposed to point-in-time restore within the same region.

Why this answer

Geo-restore for Azure SQL Database uses the most recent geo-replicated backup, which is typically within one hour. Unlike point-in-time restore, which allows restoring to any point within the retention period (up to 35 days), geo-restore does not provide a point-in-time capability; it restores to the latest geo-replicated backup. This is an important distinction when planning for disaster recovery across regions.

Exam trap

The trap here is assuming that geo-restore provides the same point-in-time restore window as standard point-in-time restore.

550
MCQhard

You are reviewing an Azure RBAC role assignment for an Azure SQL Database. The role assignment shown in the exhibit is intended to allow a user to read data from the database. However, the user reports they cannot connect to the database. What is the most likely reason?

A.The RBAC role does not grant data plane access; the user must be mapped to a database user and granted database-level permissions.
B.The principal is incorrectly specified; it should be a security group.
C.The scope is too broad; it should be at the server level.
D.The action 'Microsoft.Sql/servers/databases/read' is not valid; it should be 'Microsoft.Sql/servers/databases/dataReader'.
AnswerA

Azure RBAC roles such as Reader apply to the control plane, governing resource management rather than T-SQL connectivity. Data plane access requires a contained database user mapped to a Microsoft Entra ID login or an external provider, plus database-level permissions such as db_datareader.

Why this answer

Azure RBAC roles control management plane operations (e.g., creating or deleting resources) but do not grant access to the data plane (e.g., reading or writing data in a database). To read data from an Azure SQL Database, the user must be mapped to a database user (via a contained database user or an Azure AD user) and granted database-level permissions such as db_datareader. The RBAC role assignment shown only provides the 'Microsoft.Sql/servers/databases/read' action, which allows reading database metadata (like tags or properties) but not connecting to the database or querying tables.

Exam trap

The trap here is that candidates confuse Azure RBAC roles (management plane) with SQL database-level permissions (data plane), assuming that a role with 'read' in the name allows reading data from tables.

How to eliminate wrong answers

Option B is wrong because the principal type (user, group, or service principal) does not affect data plane access; the core issue is that RBAC does not grant data plane permissions at all. Option C is wrong because expanding the scope to the server level still only grants management plane actions (e.g., listing databases) and does not enable database connectivity or data reading. Option D is wrong because 'Microsoft.Sql/servers/databases/dataReader' is not a valid RBAC action; RBAC actions are management plane operations, and data reader access is granted via SQL-level permissions (e.g., db_datareader role) or Azure AD authentication with contained database users.

551
Multi-Selectmedium

Your organization uses Azure SQL Managed Instance and needs to implement a defense-in-depth strategy. Which THREE security controls should you implement? (Choose three.)

Select 3 answers
A.Enable advanced threat protection using Microsoft Defender for Cloud.
B.Implement server-level auditing to capture database events.
C.Create columnstore indexes on large tables to improve query performance.
D.Configure network security groups (NSGs) on the subnet to restrict inbound traffic to the managed instance.
E.Create application roles in each database to manage permissions.
AnswersA, B, D

Microsoft Defender for Cloud's advanced threat protection detects anomalous access patterns and brute-force attempts against Azure SQL Managed Instance, raising alerts for suspicious logins and potential SQL injection. This satisfies the defence-in-depth requirement by adding a detective control layer beyond authentication and network isolation, enabling rapid response to compromised credentials or exploitation attempts.

Why this answer

Option A is correct because enabling advanced threat protection via Microsoft Defender for Cloud provides detection and alerting for anomalous activities and potential vulnerabilities on Azure SQL Managed Instance, which is a core detective control in a defense-in-depth strategy. Option B is correct because server-level auditing captures database events and writes them to an audit log, providing the monitoring and traceability required for a layered security approach. Option D is correct because configuring network security groups (NSGs) on the subnet restricts inbound traffic to the managed instance, enforcing network-level segmentation and reducing the attack surface, which is a fundamental preventive control.

Option C is not a security control; columnstore indexes are a performance optimization for analytical workloads and do not contribute to defense-in-depth. Option E is not the best fit because application roles manage permissions within a database but do not address the broader layered security controls expected in a defense-in-depth strategy for Azure SQL Managed Instance.

Exam trap

The trap here is that candidates often confuse performance tuning features (like columnstore indexes) or routine permission management (like application roles) with distinct security controls, failing to recognize that defense-in-depth requires separate, layered protections across network, monitoring, and auditing domains.

552
MCQeasy

You need to monitor the storage space usage of an Azure SQL Database over time. Which tool should you use?

A.Intelligent Insights
B.Azure SQL Analytics (Azure Monitor)
C.Query Store
D.SQL Server Management Studio (SSMS)
AnswerB

Azure SQL Analytics consumes the database's resource-usage telemetry, including storage consumption, and surfaces it in Azure Monitor with historical trending. This satisfies the requirement to track storage space usage over time rather than only viewing a current value.

Why this answer

Azure SQL Analytics in Azure Monitor provides historical storage metrics. Option A is wrong because Intelligent Insights is for proactive diagnostics, not storage monitoring. Option C is wrong because Query Store focuses on query performance.

Option D is wrong because SSMS does not provide historical monitoring.

553
MCQmedium

You manage an Azure SQL Database that supports a reporting workload. Users report that a complex aggregation query returns different elapsed times throughout the day, but the logical reads remain consistent. You need to determine whether the query is experiencing CPU pressure or waiting on resources. Which Query Store view should you use to analyze wait statistics for the query?

A.sys.query_store_plan
B.sys.query_store_runtime_stats
C.sys.query_store_query_text
D.sys.query_store_wait_stats
AnswerD

This view captures wait statistics aggregated by query and plan, including wait categories and total wait time. It shows whether the query is waiting on CPU, I/O, locks, or other resources. Since the user needs to distinguish CPU pressure from resource waits, this is the correct source. It provides the necessary wait data to make that determination.

Why this answer

To analyze wait statistics for a specific query in Query Store, you must use the sys.query_store_wait_stats view. It aggregates wait times by query and plan, allowing you to see the wait categories and durations. This directly addresses the need to differentiate between CPU pressure and resource waits.

The other views provide runtime stats, plan details, or query text, but none include wait information.

Exam trap

The trap here is assuming that runtime statistics alone can reveal wait types, when in fact wait categories are stored separately in the wait stats view.

554
MCQmedium

You are a database administrator for a healthcare company that uses Azure SQL Database. You need to automate the process of exporting a BACPAC file to Azure Blob Storage every day at 3:00 AM. You want to minimize development effort and use an Azure-native service. What should you use?

A.SQL Server Agent job on an Azure virtual machine that runs a T-SQL script using BACKUP DATABASE TO URL.
B.Azure Logic Apps with a recurrence trigger and a SQL Server connector to execute an export command.
C.Azure Automation runbook with a PowerShell script that uses the New-AzSqlDatabaseExport cmdlet.
D.Azure Data Factory pipeline with a copy activity that exports the database to Blob Storage.
AnswerC

Azure Automation provides a serverless way to run PowerShell scripts on a schedule. The New-AzSqlDatabaseExport cmdlet initiates a BACPAC export to Azure Blob Storage. This requires minimal development effort, as the cmdlet handles the export, and Automation manages the schedule and execution. It is an Azure-native solution that directly meets the requirement.

Why this answer

Azure Automation runbooks can run PowerShell on a schedule, and the New-AzSqlDatabaseExport cmdlet is designed to export an Azure SQL Database to a BACPAC in Blob Storage. This combination is Azure-native, requires minimal code, and directly automates the daily export. Other options either use unsupported commands, require more development, or do not produce BACPAC files.

Exam trap

The trap here is assuming that any data movement service can create a BACPAC, when only specific cmdlets or the portal export feature produce that format.

555
MCQmedium

You are the database administrator for a company that uses Azure SQL Database. The company has a policy that database administrators must not have access to sensitive data in a specific table named EmployeeSalaries. You need to implement a solution that allows DBAs to manage the database but prevents them from viewing or modifying data in the EmployeeSalaries table. What should you implement?

A.Dynamic Data Masking (DDM) on the sensitive columns.
B.Always Encrypted with column encryption keys stored in Azure Key Vault, and restrict DBA access to the keys.
C.Transparent Data Encryption (TDE) with a customer-managed key.
D.Row-Level Security (RLS) with a filter predicate that excludes DBAs.
AnswerB

Always Encrypted ensures that data is encrypted at the client and never revealed to the database engine. By storing the column encryption keys in Azure Key Vault and not granting DBAs access to the keys, DBAs cannot decrypt the data even if they have full database permissions. This satisfies the requirement to prevent DBAs from viewing or modifying sensitive data.

Why this answer

Always Encrypted is designed to protect sensitive data from high-privileged users like DBAs by ensuring that encryption and decryption occur on the client side. The database engine never sees the plaintext data or the encryption keys. By storing the column encryption keys in Azure Key Vault and not granting DBAs access to the keys, DBAs cannot view or modify the data, even with sysadmin privileges.

This meets the policy requirement.

Exam trap

The trap here is assuming that DDM or RLS can restrict DBAs, but these features are bypassed by users with elevated permissions like sysadmin or db_owner.

556
MCQeasy

You are automating the creation of an Azure SQL database. You need to ensure that the deployment is idempotent using Azure Resource Manager (ARM) templates. Which deployment mode should you use?

A.Complete
B.Automatic
C.Incremental
D.Validate
AnswerC

Incremental mode deploys resources without deleting existing ones, so re-running the same ARM template leaves unchanged resources intact and creates only missing ones. This satisfies the idempotency requirement, whereas Complete mode would delete resources absent from the template, breaking repeated deployments.

Why this answer

Incremental deployment mode is the default ARM template mode and is idempotent: resources declared in the template are created or updated, and existing resources not in the template are left untouched. This makes repeated deployments safe and consistent, which is exactly what idempotency requires. Complete mode, by contrast, deletes resources in the resource group that are not in the template, so it is not idempotent in the safe sense.

Exam trap

DP-300 often tests the misconception that Complete mode is 'more thorough' and therefore better for automation, when in fact Complete mode's deletion behavior breaks idempotency and can destroy resources not in the template.

How to eliminate wrong answers

Option A is wrong because Complete mode deletes any resources in the target resource group that are not defined in the template, which is destructive and not idempotent for repeated deployments. Option B is wrong because 'Automatic' is not a valid ARM deployment mode; the valid modes are Incremental, Complete, and Validate. Option D is wrong because Validate mode only checks template syntax and permissions without actually deploying resources, so it cannot be used to create or update a database.

557
Multi-Selecteasy

Which TWO are benefits of using a failover group for Azure SQL Database? (Select two.)

Select 2 answers
A.Allows the secondary database to be readable for reporting
B.Enables transparent data encryption (TDE) across regions
C.Provides a single read/write listener endpoint for the primary database
D.Automatically balances read queries between primary and secondary
E.Supports synchronous replication between primary and secondary
AnswersA, C

A failover group replicates databases to a secondary server that can be opened read-only, letting reporting workloads query the secondary without impacting the primary. This satisfies the requirement for an offload reporting target while retaining failover capability.

Why this answer

Option A is correct because a failover group allows you to configure the secondary database as readable, enabling read-only workloads such as reporting to be offloaded to the secondary replica. Option C is correct because a failover group provides a read/write listener endpoint (e.g., <failover-group>.database.windows.net) that automatically redirects connections to the current primary after a failover, giving applications a stable connection string. Option B is not a benefit specific to failover groups; TDE is a database-level encryption feature that can be enabled independently and is not provided or extended across regions by a failover group.

Option D is incorrect because failover groups do not automatically load-balance read queries between primary and secondary; read-only routing must be configured and is not automatic balancing. Option E is incorrect because Azure SQL Database failover groups use asynchronous replication, not synchronous replication, between the primary and secondary servers.

558
MCQmedium

You manage an Azure SQL Database in the Business Critical service tier. The database has a zone-redundant configuration. During a planned maintenance event, you need to ensure that the database remains online with no data loss and minimal downtime. What should you configure?

A.Enable auto-failover groups with a secondary database in a different region.
B.Configure active geo-replication to a secondary database in the same region.
C.Ensure the database is configured with zone redundancy and rely on the built-in high availability architecture.
D.Create a long-term retention policy and restore the database from backup after maintenance.
AnswerC

In the Business Critical tier, zone redundancy replicates compute and storage across multiple availability zones. During planned maintenance, Azure performs a rolling upgrade, and the built-in high availability architecture automatically fails over to a healthy replica with no data loss and minimal downtime. This is the correct configuration to meet the stated requirements.

Why this answer

Zone redundancy in the Business Critical tier replicates both compute and storage across availability zones, enabling automatic failover during planned maintenance with no data loss and minimal downtime. Cross-region solutions like failover groups or geo-replication address disaster recovery, not local high availability. Backup and restore is not a high availability mechanism.

Exam trap

The trap here is confusing cross-region disaster recovery features with local high availability during maintenance.

559
MCQhard

You are the database administrator for a large e-commerce company that uses Azure SQL Database for its transactional systems. The environment consists of 100 databases spread across 10 elastic pools in different regions. You need to implement an automated solution to perform the following tasks every night: (1) Run integrity checks (DBCC CHECKDB) on all databases, (2) Rebuild indexes with fragmentation > 30%, (3) Update statistics with full scan for databases that have had significant data changes (>20% of rows). The solution must minimize manual intervention, provide centralized logging, and be resilient to failures (e.g., if one database fails, the others should continue). Which approach should you use?

A.Create an Elastic Database Job with step scripts for each maintenance task, targeting all databases, and configure retry logic.
B.Create a SQL Agent job on each server to run a maintenance script.
C.Use Azure Data Factory pipelines with a ForEach activity to execute stored procedures.
D.Use Azure Automation runbooks with Invoke-SqlCmd to loop through each database.
AnswerA

Elastic Database Jobs run T-SQL against every database in the target group from a single job agent, satisfying the centralised, low-touch requirement across 100 databases in 10 pools. Per-database execution isolates failures, so one database erroring does not halt the others, and built-in retry logic plus job history logging meet the resilience and centralised logging constraints.

Why this answer

Elastic Database Jobs are purpose-built for running T-SQL across many Azure SQL databases, including those in elastic pools across regions. You can define step scripts for DBCC CHECKDB, index rebuilds, and statistics updates, target all databases, and configure retry logic so a failure on one database doesn't stop the others — meeting the automation, centralized logging, and resilience requirements.

Exam trap

DP-300 often tests the misconception that Azure SQL Database supports SQL Agent jobs like SQL Server — candidates pick SQL Agent jobs, forgetting that Azure SQL Database is PaaS and lacks SQL Agent.

How to eliminate wrong answers

Option B is wrong because Azure SQL Database does not expose SQL Agent; SQL Agent is only available on SQL Server (IaaS/Managed Instance), so you cannot create SQL Agent jobs on Azure SQL Database servers. Option C is wrong because ADF pipelines with ForEach can call stored procedures but lack native per-database retry/continue-on-error semantics and centralized job logging tailored to database maintenance. Option D is wrong because Azure Automation runbooks with Invoke-SqlCmd require managing credentials, handling connectivity per database, and lack built-in job history and retry semantics for hundreds of databases.

560
MCQeasy

Your organization uses Azure SQL Database and wants to restrict access to only specific on-premises IP addresses. The database has a public endpoint. Which security feature should you configure?

A.Enable 'Allow Azure services and resources to access this server' in the firewall settings.
B.Enable Always Encrypted with secure enclaves.
C.Set firewall rules to allow specific on-premises IP ranges.
D.Create a virtual network service endpoint for SQL.
E.Configure a private endpoint for the database.
AnswerC

Server-level and database-level firewall rules filter inbound connections by source IP address at the Azure SQL gateway, permitting only the listed on-premises ranges while blocking all other public traffic. This directly satisfies the requirement to restrict the public endpoint to specific on-premises addresses.

Why this answer

To restrict access to specific on-premises IP addresses, you should configure firewall rules to allow those IP ranges. Setting a firewall rule ensures that only traffic from allowed IP addresses can reach the database. Option C directly addresses this requirement.

Exam trap

Candidates might consider enabling 'Allow Azure services' or using virtual network endpoints, but those are for Azure service access or private network integration, not for restricting on-premises IPs.

How to eliminate wrong answers

Option B is wrong because Always Encrypted with secure enclaves is a data encryption feature that protects sensitive data at rest and in use, but it does not control network-level access or firewall rules; it addresses data confidentiality, not connectivity restrictions. Option D is wrong because creating a virtual network service endpoint for SQL allows traffic from a specific Azure virtual network to bypass the public endpoint, but it does not restrict access to only specific Azure services and on-premises IPs; it requires additional network rules and does not inherently block all other traffic. Option E is wrong because configuring a private endpoint for the database provides a private IP address within a virtual network, eliminating public endpoint exposure, but it does not allow on-premises IP access unless combined with a VPN or ExpressRoute; it also does not selectively permit specific Azure services without additional configuration.

561
MCQeasy

You manage an Azure SQL Database that experiences periodic performance degradation. You need to identify the top queries by CPU consumption over the last hour. Which dynamic management view should you query?

A.sys.dm_exec_sessions
B.sys.dm_exec_query_plan
C.sys.dm_exec_query_stats
D.sys.dm_exec_requests
AnswerC

sys.dm_exec_query_stats aggregates cumulative execution statistics per cached query plan, including total worker time, so ordering by CPU time over the last hour identifies the top CPU-consuming queries. It satisfies the need to rank queries by CPU consumption.

Why this answer

sys.dm_exec_query_stats returns one row per cached query plan and includes cumulative execution statistics such as total_worker_time (CPU), total_elapsed_time, and execution_count. Aggregating total_worker_time over the last hour identifies the top CPU-consuming queries. This is the standard DMV for query-level performance analysis in Azure SQL Database.

Exam trap

DP-300 often tests the distinction between DMVs that report cumulative historical statistics (sys.dm_exec_query_stats) and those that report only the current instant (sys.dm_exec_requests) — candidates pick the 'requests' DMV because it sounds like it tracks query activity.

How to eliminate wrong answers

Option A is wrong because sys.dm_exec_sessions shows session-level metadata (login name, status, host) but no per-query CPU consumption metrics. Option B is wrong because sys.dm_exec_query_plan returns the XML execution plan for a given plan handle — it describes how a query executes but contains no runtime CPU statistics. Option D is wrong because sys.dm_exec_requests shows currently executing requests only, so it cannot surface queries that already completed within the last hour.

562
MCQmedium

Your company uses Azure SQL Database and needs to restrict access to a specific column containing credit card numbers. Only users with the 'CreditCardViewer' role should see the full number; others should see only the last four digits. Which feature should you implement?

A.Always Encrypted
B.Row-Level Security
C.Column-level security with GRANT
D.Dynamic Data Masking
AnswerD

Dynamic Data Masking applies masking rules at query time, so non-privileged users receive only the last four digits of the credit card column while CreditCardViewer role members see full values. This satisfies the requirement without altering stored data or duplicating the column.

Why this answer

Dynamic Data Masking (DDM) is the correct choice because it allows you to obfuscate sensitive data in query results without changing the underlying database. You can define a mask on the credit card column that shows only the last four digits to users without the 'CreditCardViewer' role, while users with that role can be granted the UNMASK permission to see the full value.

Exam trap

The trap here is that candidates often confuse Dynamic Data Masking with Column-Level Security (GRANT), not realizing that GRANT cannot partially reveal data—it only provides all-or-nothing column access, whereas DDM is designed specifically for partial obfuscation based on permissions.

How to eliminate wrong answers

Option A is wrong because Always Encrypt encrypts data at the client side, preventing the database engine from seeing plaintext values, which would block the ability to selectively show the last four digits based on a database role. Option B is wrong because Row-Level Security controls access to entire rows based on a predicate function, not to individual columns or partial data within a column. Option C is wrong because column-level security with GRANT can restrict access to an entire column, but it cannot partially mask the data—it either allows full visibility or no visibility, not a masked view showing only the last four digits.

563
MCQhard

You manage a SQL Server 2019 Always On availability group on Azure Virtual Machines. The availability group has two synchronous replicas in an availability set and one asynchronous replica in a different Azure region. During a planned maintenance window, you need to patch the operating system on the primary replica with minimal downtime and no data loss. What should you do first?

A.Take the primary replica offline and patch it, then bring it back online.
B.Fail over to the asynchronous replica in the remote region.
C.Perform a manual failover of the availability group to the synchronous secondary replica.
D.Set the availability group to asynchronous commit mode and then patch the primary.
AnswerC

Performing a manual failover to a synchronous secondary ensures no data loss because the secondary is synchronized, and it moves the primary role away from the node being patched. This allows you to patch the former primary while the availability group remains online and the application continues to use the listener. It is the standard first step for patching with minimal downtime and no data loss.

Why this answer

To patch the primary replica with no data loss and minimal downtime, you must first move the primary role to a synchronous secondary replica using a manual failover. Because the secondary is synchronized, the failover is seamless and lossless. After the failover, the former primary becomes a secondary and can be patched while the availability group remains online and accessible through the listener.

Exam trap

The trap here is assuming that patching the primary in place or failing over to an asynchronous replica is acceptable, when only a manual failover to a synchronous secondary guarantees no data loss and minimal downtime.

564
MCQeasy

You are monitoring an Azure SQL Database that uses the General Purpose service tier. You need to configure an alert that triggers when the database's CPU usage exceeds 90% for 10 minutes. What should you use?

A.SQL Server Agent job that queries sys.dm_db_resource_stats and sends an email.
B.Azure SQL Database automatic tuning with CPU-based recommendations.
C.Azure Monitor metric alert on the CPU percentage metric.
D.Query Store alert configured to trigger on high CPU usage.
AnswerC

Azure Monitor provides platform metrics for Azure SQL Database, including CPU percentage. You can create a metric alert that evaluates the CPU percentage metric over a 10-minute window and triggers when the average exceeds 90%. This is the standard and recommended way to set up such alerts, as it integrates with Azure Monitor and supports actions like email or webhook notifications.

Why this answer

Azure Monitor metric alerts are the correct mechanism for alerting on Azure SQL Database metrics. You can create a metric alert rule that monitors the CPU percentage metric and triggers when the average exceeds 90% over a 10-minute period. This is a native, scalable, and integrated solution that supports various notification actions.

Exam trap

The trap here is thinking that Query Store or automatic tuning can send alerts, when they are diagnostic and optimization tools, not alerting services.

565
MCQmedium

Your Azure SQL Database is experiencing a sudden increase in wait time due to PAGEIOLATCH_SH waits. What should you do to reduce these waits?

A.Increase the database max memory
B.Add appropriate indexes to reduce table scans
C.Enable page compression on large tables
D.Force parameterization of queries
AnswerB

PAGEIOLATCH_SH waits indicate sessions waiting on data pages read from storage, typically caused by scans. Adding appropriate indexes reduces table scans, cutting physical I/O and shortening those waits at their source rather than masking symptoms through scaling.

Why this answer

PAGEIOLATCH_SH waits indicate I/O bottlenecks caused by excessive page reads from disk. Adding appropriate indexes reduces the number of pages read by enabling more efficient data access (e.g., index seeks instead of table scans), directly reducing I/O. Option A is incorrect because increasing max memory does not address the underlying query inefficiency driving I/O.

Option C is incorrect because page compression reduces storage but may increase CPU and does not primarily reduce I/O waits. Option D is incorrect because forcing parameterization improves plan reuse but does not target I/O reduction.

566
MCQmedium

You are managing an Azure SQL Managed Instance that hosts multiple databases for a financial application. You need to implement a security solution that meets compliance requirements by auditing all database activity and sending the audit logs to a centralized Log Analytics workspace for analysis. The solution must also support real-time alerts on suspicious activities. What should you configure?

A.Enable Microsoft Defender for Cloud and configure SQL vulnerability assessment.
B.Enable auditing to a storage account and use Microsoft Intune for monitoring.
C.Enable auditing to a Log Analytics workspace and integrate with Microsoft Sentinel.
D.Enable Microsoft Purview Data Map for the managed instance.
AnswerC

Auditing to a Log Analytics workspace centralises all database activity for compliance analysis, while Microsoft Sentinel ingests those same logs to provide real-time analytics rules and alerts on suspicious activity, satisfying both the centralised logging and real-time alerting constraints.

Why this answer

Auditing to a Log Analytics workspace allows centralized collection of audit logs, which can then be integrated with Microsoft Sentinel for real-time analytics, threat detection, and automated alerting on suspicious activities. This meets both the compliance requirement for auditing and the operational need for real-time alerts.

Exam trap

The trap here is that candidates may confuse Microsoft Defender for Cloud (which provides vulnerability assessment and security recommendations) with a full auditing and SIEM solution, or mistakenly think that a storage account plus Intune can provide real-time alerting, when in fact only Log Analytics with Sentinel delivers both centralized auditing and real-time threat detection.

How to eliminate wrong answers

Option A is wrong because Microsoft Defender for Cloud and SQL vulnerability assessment focus on security posture and vulnerability scanning, not on auditing all database activity or sending logs to a Log Analytics workspace for real-time alerts. Option B is wrong because while auditing to a storage account captures logs, Microsoft Intune is a mobile device management (MDM) and endpoint management tool, not a monitoring or alerting solution for database audit logs. Option D is wrong because Microsoft Purview Data Map is designed for data governance, cataloging, and lineage, not for auditing database activity or providing real-time security alerts.

567
MCQeasy

You are a database administrator for a hospital that uses Azure SQL Database to store patient records. The hospital's security policy requires that all database access be authenticated using Microsoft Entra ID (formerly Azure AD). You have already created a Microsoft Entra ID user for yourself and granted you the 'db_owner' role. You now need to create a new Microsoft Entra ID user for a nurse who needs read-only access to the database. What should you do first?

A.In the Azure portal, add the nurse as a server-level Microsoft Entra admin
B.Create a SQL login for the nurse on the logical server and then create a user in the database mapped to that login
C.Connect to the master database using SQL authentication and run 'CREATE USER [nurse@hospital.onmicrosoft.com] FROM EXTERNAL PROVIDER'
D.Connect to the database using your Microsoft Entra account and run 'CREATE USER [nurse@hospital.onmicrosoft.com] FROM EXTERNAL PROVIDER'
AnswerD

Creating a contained database user from an external provider maps the Microsoft Entra identity into the database, which must happen before any role membership or permission grant. The db_owner connection is required because CREATE USER demands ALTER ANY USER permission, which the nurse's account does not yet hold.

Why this answer

The nurse must be created as a contained database user mapped to Microsoft Entra ID. Since the hospital uses Azure SQL Database and requires Microsoft Entra authentication, you must connect to the user database (not master) using your Microsoft Entra account (which has db_owner privileges) and run 'CREATE USER [nurse@hospital.onmicrosoft.com] FROM EXTERNAL PROVIDER'. This creates a database user that authenticates via Microsoft Entra ID without requiring a server-level login, aligning with the security policy.

Exam trap

The trap here is that candidates mistakenly think they need to create a login in the master database first (as in SQL Server or Azure SQL Managed Instance), but Azure SQL Database uses contained database users for Microsoft Entra authentication, so the 'CREATE USER ... FROM EXTERNAL PROVIDER' must be run directly in the user database by a Microsoft Entra-authenticated user.

How to eliminate wrong answers

Option A is wrong because adding the nurse as a server-level Microsoft Entra admin grants full administrative privileges over the logical server, far exceeding the required read-only access and violating the principle of least privilege. Option B is wrong because Azure SQL Database does not support SQL logins for Microsoft Entra users; you cannot create a SQL login mapped to a Microsoft Entra identity, and the approach of creating a SQL login and then a database user is for SQL authentication, not Microsoft Entra authentication. Option C is wrong because connecting to the master database with SQL authentication is not possible if the policy requires Microsoft Entra authentication, and 'CREATE USER ...

FROM EXTERNAL PROVIDER' must be run in the user database, not master, and must be executed by a Microsoft Entra-authenticated principal.

568
MCQmedium

You are the DBA for a company using Azure SQL Database. The security team requires that all data at rest in the database be encrypted with a customer-managed key (CMK) stored in Azure Key Vault, and that the DBA team be able to rotate the key without any downtime. You have already created an Azure Key Vault and an RSA 2048-bit key. What should you do next to meet these requirements?

A.Enable Always Encrypted with a column master key stored in Azure Key Vault.
B.Enable Transparent Data Encryption (TDE) with a service-managed key, then export the key to Azure Key Vault.
C.Configure Azure Disk Encryption on the underlying virtual hard disks of the Azure SQL Database.
D.In the Azure SQL logical server's Transparent Data Encryption settings, select Customer-managed key and choose the Key Vault key.
AnswerD

Azure SQL Database supports TDE with customer-managed keys stored in Azure Key Vault. By configuring the logical server's TDE settings to use a customer-managed key, you enable encryption at rest with your own key. Key rotation is supported by creating a new key version in Key Vault and updating the server configuration, with no downtime. This meets all requirements.

Why this answer

Configuring Transparent Data Encryption (TDE) with a customer-managed key in Azure Key Vault is the correct approach. TDE encrypts the database, backups, and logs at rest. Using a customer-managed key gives the organization control over the key and allows key rotation without downtime.

The other options either do not provide customer-managed keys or are not applicable to Azure SQL Database.

Exam trap

The trap here is confusing Always Encrypted with TDE; Always Encrypted protects specific columns, not the entire database at rest.

569
Multi-Selecteasy

You are configuring authentication for Azure SQL Database. Which TWO of the following are supported authentication methods?

Select 2 answers
A.Windows authentication using Kerberos.
B.Microsoft Entra ID authentication with a service principal.
C.OAuth 2.0 token authentication.
D.SQL authentication with a username and password.
E.Certificate-based authentication for SQL logins.
AnswersB, D

Microsoft Entra ID authentication supports service principals, which are non-interactive identities used by applications. This satisfies the scenario's need for a supported authentication method, since the service principal authenticates via token rather than a stored SQL password, integrating with Microsoft Entra ID directory-based identity management.

Why this answer

Option B is correct because Azure SQL Database natively integrates with Microsoft Entra ID (formerly Azure AD), and service principals (app registrations) can be granted access and authenticate via Entra ID tokens, which is a fully supported authentication method. Option D is correct because SQL authentication using a login name and password is a core, supported authentication method for Azure SQL Database (created via CREATE LOGIN or the portal). Option A is not supported because Azure SQL Database does not use Windows/Kerberos authentication; Kerberos-based Windows authentication applies to on-premises SQL Server or Azure SQL Managed Instance with AD integration, not Azure SQL Database.

Option C is not a distinct supported method because OAuth 2.0 tokens are the underlying mechanism used by Entra ID authentication, not a separately configurable authentication method for SQL logins. Option E is not supported because Azure SQL Database does not support certificate-based authentication for SQL logins; certificate authentication applies to SQL Server on-premises or Azure SQL Managed Instance.

Exam trap

The trap here is that candidates often confuse supported authentication methods for Azure SQL Database with those available for on-premises SQL Server, mistakenly selecting Windows authentication or certificate-based SQL logins, which are not supported in Azure SQL Database.

570
MCQhard

You manage an Azure SQL Managed Instance that hosts a database with a high volume of transactions. You notice that the transaction log is growing rapidly and is not being truncated. You need to identify the cause and resolve the issue. What should you do?

A.Increase the maximum size of the transaction log file.
B.Identify and resolve long-running transactions or replication delays.
C.Change the database to the Simple recovery model.
D.Shrink the transaction log file to reclaim space.
AnswerB

In the Full recovery model, the transaction log cannot be truncated until all transactions are committed and log records are backed up or replicated. Long-running transactions or replication delays hold log records, preventing truncation and causing growth. Resolving these issues allows the log to truncate normally. This is the correct approach because it addresses the root cause without compromising recovery capabilities.

Why this answer

The correct action is to identify and resolve long-running transactions or replication delays. In the Full recovery model, log truncation is blocked by active transactions or replication. Resolving these allows the log to truncate, reclaiming space.

Other options either compromise recovery (Simple model) or treat symptoms (shrink, increase size). Addressing the root cause is essential for a healthy transaction log.

Exam trap

The trap here is assuming that shrinking the log or changing the recovery model is a quick fix, without addressing the underlying truncation delay.

571
MCQeasy

You have an Azure SQL Database that uses the General Purpose service tier. The database is critical and you need to ensure that it remains available during a planned patching event that updates the underlying hardware. What does Azure SQL Database provide to maintain availability during such events?

A.The database is taken offline during patching and restored afterward.
B.You must manually fail over to a secondary database to avoid downtime.
C.Zone-redundant replicas that ensure zero downtime.
D.Automated failover to a built-in standby replica with minimal downtime.
AnswerD

The General Purpose tier uses remote storage with locally attached compute and maintains a built-in standby replica. During planned hardware patching, Azure performs automated failover to that standby, keeping the database online with minimal downtime, satisfying the availability requirement without manual intervention.

Why this answer

Azure SQL Database provides automated failover to a built-in standby replica with minimal downtime during planned patching events. This is part of the built-in high availability architecture, where the database runs on a primary replica and maintains a secondary replica. During patching, a failover occurs to the secondary, ensuring continuity.

Exam trap

The trap is thinking that zone redundancy is required for high availability during patching, when in fact the built-in standby replica handles it even without zone redundancy.

How to eliminate wrong answers

Option A is wrong because the database is not taken offline; Azure SQL Database is designed for high availability. Option B is wrong because manual failover is not required; the failover is automatic. Option C is wrong because zone-redundant replicas are an optional configuration for higher availability across availability zones, but even without them, the built-in standby replica provides failover during patching.

The question does not specify zone redundancy, and the General Purpose tier includes built-in high availability with a standby replica.

572
MCQhard

You administer a SQL Managed Instance in the West Europe region. You need to create a disaster recovery replica in North Europe with automated failover. The replica must be readable and support backups. What should you configure?

A.Set up log shipping from West Europe to North Europe.
B.Configure active geo-replication between the instances.
C.Create a failover group, but note the secondary is not readable.
D.Create a failover group with the secondary instance in North Europe.
AnswerD

A failover group provides an auto-failover endpoint and a readable secondary, satisfying the automated failover and read-access requirements. The secondary instance in North Europe also supports backups, meeting the cross-region disaster recovery constraint. Geo-replication alone lacks the automatic failover that failover groups deliver.

Why this answer

SQL Managed Instance supports failover groups for automated failover between regions, and the secondary instance in a failover group is readable and supports backups. Option A is incorrect because log shipping is not supported for SQL Managed Instance. Option B is incorrect because active geo-replication is not supported for SQL Managed Instance; failover groups are the appropriate solution.

Option C is incorrect because the secondary instance in a failover group is readable and can be used for read-only workloads.

573
MCQmedium

A company manages an Azure SQL Database that stores sensitive customer data. The security team mandates that all connections to the database use Azure Active Directory (Azure AD) authentication and that no SQL authentication logins exist. You are tasked with implementing this requirement. What should you do first?

A.Set the server's 'Public network access' to 'Disabled'.
B.Remove the server admin login from the master database.
C.Set an Azure Active Directory admin for the Azure SQL Database server.
D.Deny the CONNECT permission to all SQL authentication logins.
AnswerC

Setting a Microsoft Entra ID admin on the logical server is the prerequisite that enables Entra authentication; only after this can you create contained database users and remove SQL logins, satisfying the mandate that no SQL authentication exists.

Why this answer

Before you can enforce Azure AD-only authentication, you must first designate an Azure AD admin for the Azure SQL Database server. This admin is the only identity that can manage Azure AD users and permissions in the database, and once set, you can then remove or disable SQL authentication logins. Without an Azure AD admin, there is no way to authenticate or manage Azure AD principals within the database, making the transition impossible.

Exam trap

The trap here is that candidates often confuse disabling network access or removing permissions with actually changing the authentication model, but the first required step is always to establish an Azure AD admin to enable Azure AD authentication at the server level.

How to eliminate wrong answers

Option A is wrong because disabling public network access restricts network connectivity but does not affect authentication methods; SQL authentication logins would still exist and could be used if network access were re-enabled. Option B is wrong because removing the server admin login from the master database would break all administrative access before an Azure AD admin is established, potentially locking you out of the server entirely. Option D is wrong because denying CONNECT permission to SQL authentication logins does not remove the logins themselves; they remain in the database and could be re-granted permissions, and this action does not enforce Azure AD-only authentication as a policy.

574
Multi-Selecthard

Which THREE of the following are best practices for managing keys in Azure Key Vault for use with Azure SQL Database TDE?

Select 3 answers
A.Enable soft-delete and purge protection on the Key Vault.
B.Rotate the keys periodically.
C.Grant the server managed identity 'get', 'wrapKey', and 'unwrapKey' permissions.
D.Store the Key Vault in the same resource group as the SQL server.
E.Disable Key Vault auditing to reduce costs.
AnswersA, B, C

Prevents accidental key loss.

Why this answer

Enabling soft-delete and purge protection on the Key Vault is a best practice because soft-delete retains deleted keys for a configurable retention period (default 90 days), allowing recovery if a key is accidentally deleted. Purge protection prevents permanent deletion of keys even after the soft-delete retention period expires, which is critical for TDE because if the key is permanently lost, the encrypted database becomes inaccessible. Together, these features ensure that the TDE protector key is never irrevocably lost, maintaining database recoverability and compliance.

Exam trap

The trap here is that candidates often think placing the Key Vault in the same resource group simplifies management, but Microsoft explicitly recommends a separate resource group to avoid accidental deletion of the vault when the SQL server is deprovisioned.

Page 7

Page 8 of 8

All pages