DP-300 Implement a secure environment Practice Question
Exhibit
Refer to the exhibit. ```sql CREATE USER [user@contoso.com] FROM EXTERNAL PROVIDER; ALTER ROLE db_datareader ADD MEMBER [user@contoso.com]; ```
Refer to the exhibit. You run these commands in an Azure SQL Database. What is the result?
⚠ Common exam trap
Many exam-takers confuse the FROM EXTERNAL PROVIDER syntax with creating a contained database user for SQL authentication, leading them to incorrectly choose option C or A, when in fact the command explicitly maps to an Entra ID identity.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A Microsoft Entra ID user is created and granted read access to the database.
The commands create a user in an Azure SQL Database mapped to a Microsoft Entra ID (formerly Azure AD) identity. The CREATE USER statement with FROM EXTERNAL PROVIDER creates a user that corresponds to an Entra ID user or group. The ALTER ROLE statement then adds this user to the db_datareader database role, granting read access to all tables and views. Therefore, option D correctly describes the outcome: a Microsoft Entra ID user is created and granted read access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The user is created but not granted any permissions.
Why it's wrong here
The exhibited GRANT statement assigns permissions to the created user, so claiming none were granted contradicts the script. It is tempting because CREATE USER alone grants nothing, and would be correct if the GRANT line were absent from the batch.
- ✗
The commands fail because Entra ID users cannot be created in Azure SQL Database.
Why it's wrong here
Entra ID logins are created as contained database users via FROM EXTERNAL PROVIDER, so the syntax succeeds; the option mistakes authentication source for creation capability. It tempts because Entra ID identities are mastered in the directory, yet Azure SQL Database supports the database-scoped replica needed for T-SQL creation.
- ✗
A SQL Server authentication user is created and granted read access.
Why it's wrong here
The exhibited statements create a contained database user without a login, so no server-level SQL authentication user results. It is tempting because CREATE USER plus GRANT is the pattern for logins, and would be correct had the script used FROM LOGIN with a server credential.
- ✓
A Microsoft Entra ID user is created and granted read access to the database.
Why this is correct
The T-SQL CREATE USER ... FROM EXTERNAL PROVIDER statement provisions a database principal mapped to a Microsoft Entra ID identity, and the subsequent GRANT SELECT ON DATABASE grants read access, producing exactly that user with read permissions.
Go deeper
Related to this question
Learn chapter
Managing Identity and Access for Azure SQL
Key term
Azure SQL Performance Tuning
Azure SQL Performance Tuning is the process of optimizing the speed and efficiency of queries and database operations in Microsoft Azure SQL Database or SQL Managed Instance to reduce latency and improve throughput.
About these practice questions
This DP-300 question is part of Courseiva's 574-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DP-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-300 exam.