Courseiva

DP-300 · topic practice

Implement a secure environment practice questions

This domain covers securing Azure SQL Database, Azure SQL Managed Instance, and SQL Server on Azure VMs. Expect scenario questions on authentication (Microsoft Entra ID, SQL logins), authorization (roles, contained users), network isolation (private endpoints, firewall rules), data protection (TDE, Always Encrypted, Dynamic Data Masking, Ledger), auditing, and Microsoft Defender for SQL.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Implement a secure environment

What the exam tests

What to know about Implement a secure environment

You must be able to select and configure the right security control for a given scenario: Entra ID vs SQL auth, auditing destinations, TDE key management, Always Encrypted enclaves, and network restrictions. The most important thing is matching the requirement to the exact Azure SQL feature and its prerequisites.

Configuring Microsoft Entra ID authentication and contained database users for Azure SQL Database

Enabling auditing to capture successful and failed logins via Azure SQL Auditing

Implementing Always Encrypted with secure enclaves on Azure SQL Managed Instance

Managing TDE protector keys and customer-managed keys in Azure Key Vault

Watch out for

Common Implement a secure environment exam traps

  • ▸Confusing Microsoft Entra authentication with SQL authentication, or assuming Entra ID alone grants database permissions without contained users or server roles.
  • ▸Enabling auditing at the server level but forgetting database-level auditing, or misconfiguring the storage account and Log Analytics destination.
  • ▸Believing Always Encrypted with secure enclaves works without an attestation provider or without the required enclave-enabled key types.

Practice set

Implement a secure environment questions

20 questions · select your answer, then reveal the explanation

Your company has a strict policy that Azure SQL Database backups must be encrypted with customer-managed keys stored in Azure Key Vault. You configure TDE with AKV integration. After a key rotation, you find that long-running queries start failing with encryption errors. What is the most likely cause?

Your Azure SQL Database is configured with Advanced Threat Protection (ATP). You receive an alert about a SQL injection attack. After investigation, you confirm the attack was blocked. However, you need to ensure that future similar attacks are automatically prevented without manual intervention. What should you configure?

A developer reports that they cannot connect to an Azure SQL Database using Azure AD authentication. The developer is a member of an Azure AD group that has been granted db_datareader role in the database. The connection string uses Active Directory Password authentication. What is the most likely issue?

You need to ensure that all connections to an Azure SQL Database are encrypted. Which setting should you enforce?

You are deploying an Azure SQL Database that will store sensitive customer data. Compliance requirements dictate that the data must be encrypted at rest using a customer-managed key that is rotated every 90 days. You configure TDE with Azure Key Vault. What additional step is critical to ensure data remains accessible after key rotation?

Which THREE of the following are required to configure Transparent Data Encryption (TDE) with customer-managed keys in Azure Key Vault for Azure SQL Database?

You are the database administrator for a healthcare company that uses Azure SQL Database to store patient records. The database is named PatientDB. The security team mandates that all database access must be audited, and any suspicious activity must be alerted in real-time. Additionally, compliance requires that all data at rest be encrypted using a customer-managed key stored in Azure Key Vault. You have configured the following: - TDE with customer-managed key in AKV (key vault name: KV-Health, key name: PatientKey) - Azure SQL Auditing enabled, writing logs to a storage account (StorageAcctLogs) - Advanced Threat Protection (ATP) enabled with alerts sent to the security team's email - Firewall rules allowing only the application server's public IP (203.0.113.50)

A week later, the security team reports that they received an ATP alert about a potential SQL injection attack from IP 198.51.100.25. However, when they check the audit logs, they find no entries from that IP. They also notice that the database remains accessible. The security team wants to know why the audit logs do not contain the suspicious IP even though ATP detected it. What is the most likely reason?

You manage an Azure SQL Database named SalesDB that is used by a sales application. The application connects using a SQL login named 'sales_user' with a password. Recently, the security team discovered that 'sales_user' has been compromised. They have reset the password in Azure SQL Database. However, the application continues to connect successfully using the old credentials. You suspect the application might be caching the password. The security team wants to immediately revoke access for the compromised login and ensure that only a new login with a complex password is used. You also want to minimize downtime. What should you do first?

You need to configure authentication for Azure SQL Database. Which TWO options are supported?

Your organization has an Azure SQL Database server. You need to ensure that only applications running on Azure virtual machines in a specific virtual network can connect to the database. Which THREE actions should you take?

You are troubleshooting a connection issue from Azure SQL Database to Azure Storage using a managed identity. The above credential was created. What is missing from this configuration?

Exhibit

Refer to the exhibit.

```
ALTER DATABASE SCOPED CREDENTIAL MyCred
WITH IDENTITY = 'Managed Identity';
```

Your company is planning to migrate on-premises SQL Server databases to Azure SQL Managed Instance. The security team requires that all database connections be encrypted and that the server's identity be verified using a certificate from a trusted public certificate authority (CA). What should you configure?

You are setting up Azure SQL Database and need to ensure that only specific Azure services (e.g., Azure Data Factory) can access the database. What should you configure?

Your company uses Azure SQL Database and needs to audit all data modifications (INSERT, UPDATE, DELETE) for compliance. You enable SQL Database auditing and configure a storage account for logs. However, you notice that some DELETE operations are not being audited. What could be the cause?

You are implementing row-level security (RLS) in Azure SQL Database to restrict access to sales data based on the user's Azure AD identity. Which function should you use in the security policy?

Question 16hardmultiple choice
Review the full subnetting walkthrough →

You are the database administrator for a company that uses Azure SQL Database. The company has a strict security policy requiring that all database connections be encrypted using TLS 1.2 or higher and that the server certificate be validated to prevent man-in-the-middle attacks. Additionally, the company wants to ensure that only applications running on Azure virtual machines (VMs) in a specific virtual network (VNet) can access the database. The VMs use a subnet named 'AppSubnet'. You have configured the following: 1. The server 'Allow Azure Services' setting is OFF. 2. A virtual network rule is added for 'AppSubnet' with the service endpoint for Microsoft.Sql enabled. 3. The server firewall has no other rules. 4. The 'Minimum TLS version' is set to 1.2. 5. All client applications are configured to use 'Encrypt=True' and 'TrustServerCertificate=False' in their connection strings.

After deployment, you discover that connections from the VMs are failing with error: 'The certificate chain was issued by an authority that is not trusted'. What is the most likely cause of this issue?

You are designing a secure architecture for Azure SQL Managed Instance. You need to ensure that all connections to the instance are encrypted and that the instance can only be accessed from a specific virtual network. Which TWO configurations should you implement?

You are the database administrator for a company that uses Azure SQL Database. The company has a strict security policy requiring that all database connections be encrypted and that the server's firewall only allows connections from a list of approved IP addresses. You have configured the server-level firewall rules accordingly and enabled the 'Force encryption' setting on the server. However, after deployment, you notice that an application running on an Azure virtual machine is able to connect to the database even though its public IP address is not in the approved list. The virtual machine is in the same region as the database. What is the most likely cause?

Refer to the exhibit. The exhibit shows an Azure role assignment with a condition. When user@contoso.com tries to read data from the database 'proddb', what will be the effect of this condition?

Exhibit

Refer to the exhibit.

```json
{
  "role": "Azure SQL Database Contributor",
  "scope": "/subscriptions/12345/resourceGroups/ProdRG/providers/Microsoft.Sql/servers/prodserver/databases/proddb",
  "assignee": "user@contoso.com",
  "condition": "((!(ActionMatches{'Microsoft.Sql/servers/databases/read'})) OR (@Request[Microsoft.Sql/servers/databases/read:DataAction] NotExists))",
  "conditionVersion": "2.0"
}
```

Match each Azure SQL Database pricing tier to its key feature.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Single node, suitable for development and small workloads

Balanced compute and memory for most production workloads

High memory-to-core ratio for memory-intensive workloads

Low-cost option with ability to burst CPU performance

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Implement a secure environment sessions

Start a Implement a secure environment only practice session

Every question in these sessions is drawn from the Implement a secure environment domain — nothing else.

Related practice questions

Related DP-300 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the DP-300 exam test about Implement a secure environment?
You must be able to select and configure the right security control for a given scenario: Entra ID vs SQL auth, auditing destinations, TDE key management, Always Encrypted enclaves, and network restrictions. The most important thing is matching the requirement to the exact Azure SQL feature and its prerequisites.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Implement a secure environment questions in a focused session?
Yes — the session launcher on this page draws every question from the Implement a secure environment domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other DP-300 topics?
Use the topic links above to move to related areas, or go back to the DP-300 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the DP-300 exam covers. They are not copied from any real exam or dump site.