DP-300 Implement a secure environment Practice Question
Which TWO of the following are best practices for securing Azure SQL Database?
⚠ Common exam trap
Many exam-takers confuse Auditing (logging) with blocking, or TDE (encryption at rest) with SQL injection prevention, leading them to select options that sound security-related but do not perform the stated function.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable firewall rules to restrict access to specific IP addresses.
Option D is correct because Azure SQL Database firewall rules (server-level and database-level) restrict inbound connections to approved IP address ranges, reducing the exposed attack surface by denying traffic from unknown sources. Option E is correct because Microsoft Entra ID (now Microsoft Entra ID) authentication centralizes identity management, supports MFA and conditional access, and eliminates the risk of weak or shared SQL logins and passwords. Option A is incorrect because Auditing records and logs activity for compliance and forensics; it does not block or prevent malicious queries. Option B is incorrect because Transparent Data Encryption encrypts data at rest (and backups) and does nothing to stop SQL injection, which is an application-layer input validation issue. Option C is incorrect because SQL authentication with complex passwords is a weaker, legacy approach compared to Entra ID authentication, and complex passwords alone do not constitute a best practice for securing Azure SQL Database.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable Auditing to block malicious queries.
Why it's wrong here
Auditing records queries and access events to a log for later review; it is detective, not preventive, so it cannot block a malicious query in flight. Auditing is the right choice when the requirement is forensic traceability or compliance evidence of who accessed which data.
- ✗
Enable TDE to prevent SQL injection attacks.
Why it's wrong here
Transparent Data Encryption encrypts data and backups at rest; it does not parse query text, so it cannot detect or prevent SQL injection. TDE is the correct control for meeting encryption-at-rest compliance requirements, such as regulatory mandates covering database files and backup media.
- ✗
Use SQL authentication with complex passwords.
Why it's wrong here
SQL authentication relies on credentials stored in the database, which weakens least privilege because access is not tied to Microsoft Entra ID identities, conditional access or managed identities. It is tempting for legacy application compatibility, where a connection string cannot use Entra authentication.
- ✓
Enable firewall rules to restrict access to specific IP addresses.
Why this is correct
Restricting access to specific IP addresses via firewall rules satisfies the requirement to limit network exposure of Azure SQL Database. Server-level and database-level firewall rules block connections originating outside approved ranges, ensuring only known clients reach the logical server, which directly reduces the attack surface from arbitrary internet traffic.
- ✓
Use Microsoft Entra ID authentication instead of SQL authentication.
Why this is correct
Replacing SQL authentication with Microsoft Entra ID authentication centralises identity management and enables conditional access, multifactor authentication and passwordless sign-in. This directly satisfies the stem's security requirement by removing static database credentials, which are prone to credential theft and cannot enforce tenant-wide policies such as MFA or risk-based access controls.
Go deeper
Related to this question
Learn chapter
Implementing Auditing and Threat Detection
Key term
Azure SQL Firewall Rules
Azure SQL Firewall Rules are security settings that control which IP addresses or Azure services are allowed to connect to a SQL database hosted in Microsoft Azure.
Key term
Transparent Data Encryption
Transparent Data Encryption is a security feature that automatically encrypts data written to a database and decrypts it when read, without requiring any changes to the application.
About these practice questions
One of 574 original DP-300 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DP-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-300 exam.