DP-300 Configure and manage automation of tasks Practice Question
You are configuring an Azure Automation runbook to perform daily maintenance tasks on an Azure SQL Database. The runbook will run on a schedule and must securely connect to the database. Which two actions should you perform to enable the runbook to authenticate to the database? (Choose two.)
⚠ Common exam trap
Candidates often confuse management-plane roles with data-plane permissions; the Contributor role does not grant the ability to run T-SQL, and using Key Vault or service principals introduces unnecessary secret management.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable a managed identity for the Automation account
To enable an Azure Automation runbook to authenticate to Azure SQL Database securely without storing credentials, you should enable a managed identity for the Automation account and create a contained database user for that identity in the target database. These two actions allow the runbook to obtain an Microsoft Entra ID token and connect. Other options either involve secret management or grant insufficient permissions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Store the SQL admin credentials in Azure Key Vault and retrieve them in the runbook
Why it's wrong here
Storing SQL admin credentials in Key Vault is a secure way to manage secrets, but it is not necessary if you use a managed identity. The scenario asks for two actions to enable authentication; using Key Vault would be an alternative approach but would require additional steps like configuring Key Vault access and retrieving the secret. It does not leverage the managed identity, making it less optimal and not required.
- ✗
Configure the runbook to use a service principal with a client secret stored in an Automation variable
Why it's wrong here
Using a service principal with a client secret stored in an Automation variable is a valid authentication method, but it involves managing a secret, which is less secure than a managed identity. The scenario does not specify that a service principal must be used, and the goal is to securely connect. This action is not required if a managed identity is used, and it adds unnecessary complexity.
- ✓
Enable a managed identity for the Automation account
Why this is correct
Enabling a managed identity for the Automation account creates an identity in Microsoft Entra ID that the runbook can use to authenticate to Azure SQL Database without storing credentials. This is a secure, recommended practice. The identity must then be granted access to the database. This action is essential for the runbook to obtain a token and connect.
- ✗
Assign the Automation account the Contributor role on the Azure SQL Server
Why it's wrong here
Assigning the Contributor role on the Azure SQL Server grants management-plane permissions, such as the ability to create or delete databases, but does not grant data-plane access to execute T-SQL. The runbook needs to connect to the database and run queries, which requires database-level permissions. The Contributor role is insufficient and not the correct action for enabling authentication to the database.
- ✓
Create a contained database user in the target database for the managed identity
Why this is correct
After enabling the managed identity, you must create a contained database user in the target Azure SQL Database that maps to that identity. This allows the identity to authenticate and be authorized. Without this user, the managed identity cannot access the database. You also need to assign appropriate permissions, such as db_owner or specific roles, to perform maintenance tasks.
Go deeper
Related to this question
Learn chapter
Managing Identity and Access for Azure SQL
Key term
Azure SQL Performance Tuning
Azure SQL Performance Tuning is the process of optimizing the speed and efficiency of queries and database operations in Microsoft Azure SQL Database or SQL Managed Instance to reduce latency and improve throughput.
About these practice questions
Courseiva writes every DP-300 question from scratch — 574 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This DP-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-300 exam.