DP-300 Implement a secure environment Practice Question
You are a database administrator for an Azure SQL Database. You need to ensure that only specific client IP addresses can connect to the database, while all other traffic is blocked. You also need to allow Azure services to access the database. What should you configure?
⚠ Common exam trap
Many candidates confuse network security groups (NSGs) with Azure SQL firewall rules, assuming NSGs can control access to PaaS services like Azure SQL Database, when in fact NSGs only apply to resources within a virtual network and not to the public endpoint of Azure SQL.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure server-level firewall rules to allow the specific client IP addresses and enable the 'Allow Azure services and resources to access this server' setting.
Azure SQL Database uses server-level firewall rules to control inbound access. By adding rules for specific client IP addresses and enabling the 'Allow Azure services and resources to access this server' setting, you restrict connections to only those IPs while permitting Azure internal services (e.g., Azure Logic Apps, Azure Functions) to connect. This setting leverages the Azure SQL firewall, which evaluates source IP addresses against the configured rules before allowing a connection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Disable public network access and configure a service endpoint.
Why it's wrong here
Disabling public network access blocks every public connection, including the permitted client IP addresses, and service endpoints apply to virtual network subnets rather than individual addresses. It is tempting because service endpoints are correct when only resources inside a specific Azure subnet should reach the database.
- ✗
Configure a private endpoint and disable public network access.
Why it's wrong here
A private endpoint gives only private IP connectivity from a virtual network, so specific public client IP addresses cannot connect and Azure services lose their public path. It is tempting because private endpoints are the standard answer for removing public exposure entirely, which is correct when no internet clients need access.
- ✗
Configure network security group (NSG) rules on the subnet where the Azure SQL Database is deployed.
Why it's wrong here
Azure SQL Database is a platform service, so its traffic is not attached to a customer-managed subnet and NSG rules never filter connections to it. It is tempting because NSGs are the normal way to restrict traffic to IaaS virtual machines, which is the correct scenario when the database runs on a VM.
- ✓
Configure server-level firewall rules to allow the specific client IP addresses and enable the 'Allow Azure services and resources to access this server' setting.
Why this is correct
Server-level firewall rules permit the named client IP ranges, while the 'Allow Azure services' toggle opens the special 0.0.0.0 rule that lets platform-originated traffic through. Together they satisfy both constraints: specific client IPs only, plus Azure services access.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
Learn chapter
Deploying and Configuring SQL Server on Azure Virtual Machines
Key term
Azure SQL Performance Tuning
Azure SQL Performance Tuning is the process of optimizing the speed and efficiency of queries and database operations in Microsoft Azure SQL Database or SQL Managed Instance to reduce latency and improve throughput.
About these practice questions
This DP-300 question is part of Courseiva's 574-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DP-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-300 exam.