Courseiva

DP-300 Implement a secure environment Practice Question

You are a database administrator for a healthcare company. You have an Azure SQL Database that stores patient records. The database is currently accessible from the public internet via firewall rules. You need to implement a secure environment that meets the following requirements: - All traffic to the database must be private and not traverse the internet. - The database must be accessible from an Azure Virtual Machine in a specific VNet. - The solution must minimize management overhead and cost. - You need to ensure that the database can be failed over to a secondary region in case of an outage.

What should you do?

⚠ Common exam trap

DP-300 often tests the difference between VNet service endpoints and private endpoints. Candidates may confuse the two, but only private endpoints provide a private IP for the database and allow disabling public access. Also, failover groups require private endpoints in both regions for private connectivity.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a private endpoint in the VNet, disable public network access, and configure a failover group with a private endpoint in the secondary region.

Creating a private endpoint in the VNet ensures that traffic to the Azure SQL Database uses a private IP address within the VNet, never traversing the internet. Disabling public network access enforces this. A failover group with a private endpoint in the secondary region provides cross-region failover while maintaining private connectivity. This solution minimizes management overhead and cost by using managed services.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Restrict firewall rules to only the VM's public IP and enable active geo-replication.

    Why it's wrong here

    Restricting firewall rules to a public IP still routes traffic over the internet, violating the private-traffic requirement. It is tempting because firewall rules are quick and geo-replication provides secondary-region failover, but a private endpoint plus a failover group satisfies both privacy and regional resilience.

  • ✗

    Configure a point-to-site VPN from the VM to the database and set up geo-replication.

    Why it's wrong here

    A point-to-site VPN connects individual clients, not an Azure SQL Database, which has no VPN endpoint; traffic still reaches the public endpoint. It is tempting because VPNs sound private, but a private endpoint with a failover group delivers genuine private connectivity and regional failover.

  • ✓

    Create a private endpoint in the VNet, disable public network access, and configure a failover group with a private endpoint in the secondary region.

    Why this is correct

    A private endpoint gives the Azure SQL Database a private IP inside the VNet, so traffic from the VM never traverses the internet, and disabling public access enforces this. A failover group with a paired private endpoint preserves private connectivity and cross-region failover with minimal overhead.

  • ✗

    Create a VNet service endpoint and a failover group. Keep public access enabled for failover.

    Why it's wrong here

    Keeping public access enabled means traffic can still traverse the internet, breaching the private-only requirement. It is tempting because a VNet service endpoint restricts the subnet and a failover group handles regional outage, but a private endpoint is needed to remove public exposure entirely.

About these practice questions

This DP-300 question is part of Courseiva's 574-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This DP-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-300 exam.