Courseiva

DP-300 Implement a secure environment Practice Question

Which TWO of the following are valid methods to connect to Azure SQL Database securely?

⚠ Common exam trap

Test-takers frequently confuse shared access keys (a Storage concept) with SQL Database connection methods, or assume that a simple password is acceptable for security, when the exam emphasizes Microsoft Entra ID and network isolation as the secure standards.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Connect using Microsoft Entra ID authentication with multi-factor authentication.

Option A is correct because Azure SQL Database natively supports Microsoft Entra ID (Azure AD, now Microsoft Entra ID) authentication, and enforcing multi-factor authentication adds a strong identity-verification layer that eliminates static password-only credential risks. Option C is correct because a private endpoint assigns a private IP address from your virtual network to the Azure SQL logical server, so traffic traverses the Microsoft backbone via Azure Private Link instead of the public internet, removing public exposure. Option B is wrong because shared access keys are an Azure Storage construct (used for blobs, queues, tables, files), not an authentication mechanism for Azure SQL Database. Option D is wrong because connecting over the public IP without encryption (no TLS) exposes credentials and data in transit and is not a secure method. Option E is wrong because SQL authentication with a simple password is weak, lacks MFA, and is vulnerable to brute-force and credential-stuffing attacks.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Connect using Microsoft Entra ID authentication with multi-factor authentication.

    Why this is correct

    Microsoft Entra ID authentication with multi-factor authentication verifies identity through Entra ID and adds a second factor, defeating stolen-password attacks. Traffic remains encrypted via TLS, satisfying the stem's secure connection requirement without embedding credentials in connection strings.

  • ✗

    Connect using a shared access key from Azure Storage.

    Why it's wrong here

    A shared access key authenticates to Azure Storage, not to Azure SQL Database, so it cannot establish a database connection at all. It is tempting because shared access signatures are a genuine Azure credential type, but the correct methods use SQL or Microsoft Entra ID authentication over TLS or private endpoints.

  • ✓

    Connect using a private endpoint within a virtual network.

    Why this is correct

    A private endpoint assigns a private IP from your virtual network to the Azure SQL logical server, so traffic traverses the Microsoft backbone rather than the public internet. This satisfies the secure-connectivity requirement by removing public exposure and letting you restrict access through network security groups and private DNS.

  • ✗

    Connect directly using the server's public IP address without encryption.

    Why it's wrong here

    Connecting over the public IP without encryption sends credentials and data in cleartext, which Azure SQL Database rejects for secure connectivity. It is tempting when a client cannot reach a private endpoint, but the correct methods use TLS-enforced endpoints, private endpoints, or Microsoft Entra ID authentication instead.

  • ✗

    Connect using SQL authentication with a simple password.

    Why it's wrong here

    SQL authentication with a simple password provides no encryption enforcement or credential protection, so it fails the secure-connection requirement. It is tempting because SQL logins are a familiar legacy mechanism, but the correct methods rely on Microsoft Entra ID authentication, strong secrets, and TLS or private endpoints.

Go deeper

Related to this question

About these practice questions

This DP-300 question is part of Courseiva's 574-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DP-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-300 exam.