Courseiva

DP-300 Azure Private Link Practice Question

Which TWO of the following are best practices for managing firewall rules for Azure SQL Database?

⚠ Common exam trap

Many exam-takers think only one correct answer exists, but the question explicitly asks for TWO. Candidates may select Option E ('Allow Azure Services') thinking it is a best practice, but it is actually too broad and should be avoided. Auditing (Option D) is often overlooked as a management best practice, but it is essential for security governance.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use Azure Private Link to connect from Azure VNets instead of opening firewall rules to IP ranges.

Option C is correct because Azure Private Link (Private Endpoint) gives Azure SQL Database a private IP inside your VNet, so clients connect over the Microsoft backbone without any public IP firewall rules, which is the recommended way to restrict access from Azure VNets. Option D is correct because Azure Activity Logs record control-plane operations such as creating, updating, or deleting firewall rules, providing the audit trail needed to detect unauthorized or accidental rule changes. Options A and B are not best practices: IP-based rules for all clients, especially Azure services, expose the logical server to the public internet, and broad ranges like 0.0.0.0/0 defeat the purpose of a firewall. Option E is not recommended because the 'Allow Azure Services' rule (0.0.0.0) permits connections from any Azure tenant, not just your own resources, so it should be avoided in favor of Private Link or specific IP rules.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use IP-based firewall rules for all client connections, including Azure services.

    Why it's wrong here

    IP rules cannot authenticate Azure-hosted clients, whose outbound addresses are dynamic and shared, so they break or over-permit. They suit fixed on-premises or developer addresses. For Azure services, virtual network service endpoints or private endpoints provide subnet-based control, which IP ranges cannot express.

  • ✗

    Create firewall rules with broad IP ranges (e.g., 0.0.0.0/0) to simplify management.

    Why it's wrong here

    0.0.0.0/0 permits every internet address, exposing the logical server to unrestricted brute-force and credential attacks. Broad ranges suit only throwaway test servers never holding real data. Production requires narrow, named rules, or private endpoints and virtual network service endpoints that bypass public IP filtering entirely.

  • ✓

    Use Azure Private Link to connect from Azure VNets instead of opening firewall rules to IP ranges.

    Why this is correct

    Azure Private Link provides a private IP endpoint within the VNet, eliminating public IP firewall rules entirely. This satisfies the best-practise requirement to avoid exposing the database to internet ranges, reducing attack surface while maintaining connectivity from Azure VNets.

  • ✓

    Audit all firewall rule changes using Azure Activity Logs.

    Why this is correct

    Azure Activity Logs record all control-plane operations, including firewall rule modifications, providing an audit trail. This satisfies the best-practise requirement to track changes, enabling detection of unauthorised or accidental rule alterations that could weaken database security.

  • ✗

    Enable the 'Allow Azure Services' firewall rule to allow connections from Azure services.

    Why it's wrong here

    The Allow Azure Services rule opens the server to every Azure tenant's resources, not just your subscriptions, so it grants untrusted tenants access. It suits quick demos. Production should use virtual network service endpoints or private endpoints, which restrict traffic to your own subnets and cannot be spoofed by other tenants.

About these practice questions

Courseiva writes every DP-300 question from scratch — 574 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DP-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-300 exam.