DP-300 Implement a secure environment Practice Question
You are configuring authentication for Azure SQL Database. Which TWO of the following are supported authentication methods?
⚠ Common exam trap
Many candidates confuse supported authentication methods for Azure SQL Database with those available for on-premises SQL Server, mistakenly selecting Windows authentication or certificate-based SQL logins, which are not supported in Azure SQL Database.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Entra ID authentication with a service principal.
Option B is correct because Azure SQL Database natively integrates with Microsoft Entra ID (formerly Azure AD), and service principals (app registrations) can be granted access and authenticate via Entra ID tokens, which is a fully supported authentication method. Option D is correct because SQL authentication using a login name and password is a core, supported authentication method for Azure SQL Database (created via CREATE LOGIN or the portal). Option A is not supported because Azure SQL Database does not use Windows/Kerberos authentication; Kerberos-based Windows authentication applies to on-premises SQL Server or Azure SQL Managed Instance with AD integration, not Azure SQL Database. Option C is not a distinct supported method because OAuth 2.0 tokens are the underlying mechanism used by Entra ID authentication, not a separately configurable authentication method for SQL logins. Option E is not supported because Azure SQL Database does not support certificate-based authentication for SQL logins; certificate authentication applies to SQL Server on-premises or Azure SQL Managed Instance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Windows authentication using Kerberos.
Why it's wrong here
Azure SQL Database cannot join an on-premises domain for Kerberos, so Windows authentication is unavailable; Microsoft Entra ID provides the directory-based alternative. Kerberos applies to SQL Server on Azure VMs or Azure SQL Managed Instance, and would be the answer if the stem named those services.
- ✓
Microsoft Entra ID authentication with a service principal.
Why this is correct
Microsoft Entra ID authentication supports service principals, which are non-interactive identities used by applications. This satisfies the scenario's need for a supported authentication method, since the service principal authenticates via token rather than a stored SQL password, integrating with Microsoft Entra ID directory-based identity management.
- ✗
OAuth 2.0 token authentication.
Why it's wrong here
OAuth 2.0 token authentication is the mechanism Microsoft Entra ID uses internally to issue access tokens, not a separately selectable authentication method for Azure SQL Database. It is tempting because token-based access genuinely underpins Entra ID authentication and is the correct choice when building applications that acquire tokens directly.
- ✓
SQL authentication with a username and password.
Why this is correct
SQL authentication uses a database-contained login with username and password stored and validated by Azure SQL Database itself, independent of Microsoft Entra ID. It is a natively supported authentication method, satisfying the requirement for a supported option where directory-integrated identity is not used.
- ✗
Certificate-based authentication for SQL logins.
Why it's wrong here
Azure SQL Database does not accept client certificates for SQL logins; it supports SQL logins with passwords and Microsoft Entra ID authentication. Certificate authentication belongs to on-premises SQL Server or Azure SQL Managed Instance scenarios, so it would be correct if the question concerned those platforms instead.
Go deeper
Related to this question
Learn chapter
Managing Identity and Access for Azure SQL
Key term
Azure SQL Performance Tuning
Azure SQL Performance Tuning is the process of optimizing the speed and efficiency of queries and database operations in Microsoft Azure SQL Database or SQL Managed Instance to reduce latency and improve throughput.
Key term
Azure SQL Authentication
Azure SQL Authentication is the process of verifying a user's identity to access an Azure SQL database using either a username and password (SQL Authentication) or a Microsoft Entra ID (formerly Azure AD) identity.
About these practice questions
One of 574 original DP-300 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DP-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-300 exam.