DP-300 Implement a secure environment Practice Question
You administer an Azure SQL Database named HRDB. The security team requires that any connection to HRDB from outside the corporate network be blocked, but on-premises applications must continue to connect over the existing site-to-site VPN. The database currently has a public endpoint and a firewall rule allowing all Azure services. You need to restrict access so that only the VPN subnet can reach HRDB. What should you configure?
⚠ Common exam trap
The trap here is assuming that tightening firewall rules or enabling threat detection removes public exposure, when only disabling public network access and using a private endpoint actually eliminates the public listener.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Set the database's Public Network Access to Disabled and create a private endpoint in the VPN-connected virtual network.
The requirement is network isolation combined with continued VPN access. Disabling public network access closes the internet-facing endpoint, and a private endpoint in the VPN-connected VNet provides a private IP that on-premises systems can reach over the tunnel. Firewall rules and threat detection do not remove the public listener, so only the private-endpoint approach meets the stated condition.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable Microsoft Defender for SQL and set the Advanced Threat Protection alert type to 'Access from unusual location'.
Why it's wrong here
Defender for SQL detects and alerts on suspicious access patterns but does not enforce network isolation. Alerts are informational and do not prevent connections from outside the corporate network, so the public endpoint stays open and the security requirement is not satisfied.
- ✓
Set the database's Public Network Access to Disabled and create a private endpoint in the VPN-connected virtual network.
Why this is correct
Disabling public network access removes the public endpoint, and a private endpoint places the logical server inside the VPN-connected VNet so on-premises traffic flows over the private IP. This satisfies both the block-outside requirement and continued connectivity from the corporate network without exposing a public listener.
- ✗
Configure a database-level firewall rule that allows only the on-premises application's service account and deny all other logins.
Why it's wrong here
Azure SQL Database supports database-level firewall rules only for contained database users, and they do not restrict network paths. They cannot block the public endpoint or limit traffic to a VPN subnet, so the external exposure remains and the requirement is unmet.
- ✗
Add a server-level firewall rule for the VPN subnet's public IP address range and keep the public endpoint enabled.
Why it's wrong here
A firewall rule based on the VPN's public IP range would still allow traffic from anywhere that can source those addresses, and the public endpoint remains reachable. It does not meet the requirement to block all connections from outside the corporate network because the endpoint is still internet-facing.
Visual reference
Go deeper
Related to this question
Learn chapter
Migrating On-Premises Databases to Azure
Key term
Azure SQL Performance Tuning
Azure SQL Performance Tuning is the process of optimizing the speed and efficiency of queries and database operations in Microsoft Azure SQL Database or SQL Managed Instance to reduce latency and improve throughput.
Key term
Azure SQL Threat Detection
Azure SQL Threat Detection is a built-in security feature that continuously monitors your Azure SQL database for suspicious activities and sends alerts when potential threats are found.
About these practice questions
One of 574 original DP-300 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This DP-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-300 exam.