Courseiva

DP-300 Plan and implement data platform resources Practice Question

You are configuring a new Azure SQL Database. The application that will use the database requires read-only access to the database from an Azure App Service. You need to ensure that the application connects securely without embedding credentials in code, and that access is limited to the minimum required permissions. What should you do?

⚠ Common exam trap

The trap here is choosing a solution that uses credentials stored in Key Vault or granting excessive permissions like db_owner; the key is to use managed identity with least privilege.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable Microsoft Entra authentication for the Azure SQL Database, create a contained database user mapped to the App Service's managed identity, and grant the user the db_datareader role.

Enabling Microsoft Entra authentication and creating a contained database user for the App Service's managed identity eliminates credential management. Assigning the db_datareader role grants read-only access, adhering to the principle of least privilege. This approach is secure, requires no credentials in code, and limits permissions to what the application needs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Enable Microsoft Entra authentication for the Azure SQL Database, create a contained database user mapped to the App Service's managed identity, and grant the user the db_datareader role.

    Why this is correct

    Using Microsoft Entra authentication with a managed identity eliminates the need for credentials in code. The App Service's system-assigned managed identity is used to authenticate to the database. Creating a contained database user for that identity and granting db_datareader role provides read-only access with minimum permissions, meeting all requirements.

  • ✗

    Enable Microsoft Entra authentication and create a contained database user mapped to the App Service's managed identity, then grant the user the db_owner role.

    Why it's wrong here

    While this uses managed identity and avoids credentials, granting db_owner provides full control over the database, which exceeds the minimum required permissions. The application only needs read-only access, so db_datareader is the appropriate role. Using db_owner violates the principle of least privilege.

  • ✗

    Create a contained database user with a strong password and store the credentials in Azure Key Vault. Configure the App Service to retrieve the credentials from Key Vault.

    Why it's wrong here

    While storing credentials in Key Vault is better than embedding them in code, this approach still uses a password-based authentication. It does not eliminate the need to manage and rotate credentials, and it does not provide the same level of integration as managed identities. The requirement is to avoid embedding credentials in code, but this still involves credentials.

  • ✗

    Enable SQL authentication and create a login with a strong password, then configure the App Service connection string to use this login.

    Why it's wrong here

    SQL authentication requires credentials in the connection string, which would need to be stored in code or configuration. This violates the requirement to avoid embedding credentials in code. Additionally, managing SQL logins and passwords adds administrative overhead and security risks compared to managed identities.

About these practice questions

Courseiva writes every DP-300 question from scratch — 574 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This DP-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-300 exam.