Courseiva

DP-300 Implement a secure environment Practice Question

You administer an Azure SQL Database named HRDB. The security team requires that any connection to HRDB from outside the corporate network be blocked, but on-premises applications must continue to connect over the existing site-to-site VPN. The database currently has a public endpoint and a firewall rule allowing all Azure services. You need to restrict access so that only the VPN subnet can reach HRDB. What should you configure?

⚠ Common exam trap

The trap here is assuming that tightening firewall rules or enabling threat detection removes public exposure, when only disabling public network access and using a private endpoint actually eliminates the public listener.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Set the database's Public Network Access to Disabled and create a private endpoint in the VPN-connected virtual network.

The requirement is network isolation combined with continued VPN access. Disabling public network access closes the internet-facing endpoint, and a private endpoint in the VPN-connected VNet provides a private IP that on-premises systems can reach over the tunnel. Firewall rules and threat detection do not remove the public listener, so only the private-endpoint approach meets the stated condition.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable Microsoft Defender for SQL and set the Advanced Threat Protection alert type to 'Access from unusual location'.

    Why it's wrong here

    Defender for SQL detects and alerts on suspicious access patterns but does not enforce network isolation. Alerts are informational and do not prevent connections from outside the corporate network, so the public endpoint stays open and the security requirement is not satisfied.

  • ✓

    Set the database's Public Network Access to Disabled and create a private endpoint in the VPN-connected virtual network.

    Why this is correct

    Disabling public network access removes the public endpoint, and a private endpoint places the logical server inside the VPN-connected VNet so on-premises traffic flows over the private IP. This satisfies both the block-outside requirement and continued connectivity from the corporate network without exposing a public listener.

  • ✗

    Configure a database-level firewall rule that allows only the on-premises application's service account and deny all other logins.

    Why it's wrong here

    Azure SQL Database supports database-level firewall rules only for contained database users, and they do not restrict network paths. They cannot block the public endpoint or limit traffic to a VPN subnet, so the external exposure remains and the requirement is unmet.

  • ✗

    Add a server-level firewall rule for the VPN subnet's public IP address range and keep the public endpoint enabled.

    Why it's wrong here

    A firewall rule based on the VPN's public IP range would still allow traffic from anywhere that can source those addresses, and the public endpoint remains reachable. It does not meet the requirement to block all connections from outside the corporate network because the endpoint is still internet-facing.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

Go deeper

Related to this question

About these practice questions

One of 574 original DP-300 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This DP-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-300 exam.