DP-300 Implement a secure environment Practice Question
You are configuring Azure SQL Database firewall rules. You need to allow a range of IP addresses (192.168.1.0 to 192.168.1.255) to connect to the database. Which firewall rule should you create?
⚠ Common exam trap
A common mix-up: candidates confuse Azure SQL firewall rules with on-premises firewall or network ACLs, where reversed ranges or single-IP entries might be accepted, but Azure SQL strictly requires a valid start ≤ end IP and does not support CIDR notation, leading to errors if you try to use a subnet mask or reversed order.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Start IP: 192.168.1.0, End IP: 192.168.1.255
Azure SQL Database firewall rules require a contiguous range of IP addresses defined by a start and end IP. The range 192.168.1.0 to 192.168.1.255 exactly covers the specified /24 subnet, allowing all hosts in that block to connect. This is the standard method for permitting a subnet in Azure SQL firewall configuration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Start IP: 192.168.0.0, End IP: 192.168.2.255
Why it's wrong here
This range spans 192.168.0.0–192.168.2.255, permitting 768 addresses rather than the required 256, so it over-grants access. A single rule with Start 192.168.1.0 and End 192.168.1.255 matches the /24 exactly; the wider range would only suit a scenario genuinely covering three subnets.
- ✓
Start IP: 192.168.1.0, End IP: 192.168.1.255
Why this is correct
Azure SQL Database firewall rules accept a contiguous start and end IP range, so 192.168.1.0 to 192.168.1.255 covers the entire /24 subnet in a single rule, satisfying the requirement to permit every address in that range.
- ✗
Start IP: 192.168.1.255, End IP: 192.168.1.0
Why it's wrong here
The start IP exceeds the end IP, so the rule is invalid and Azure SQL Database rejects it. It is tempting because the two boundary addresses of the required range are both present, but the ordering is reversed; the correct rule must list 192.168.1.0 as start and 192.168.1.255 as end.
- ✗
Start IP: 192.168.1.0, End IP: 192.168.1.0
Why it's wrong here
A start and end IP of 192.168.1.0 covers only that single address, leaving the other 254 hosts in the range blocked. It is tempting because the start IP matches the range's first octet, but Azure SQL firewall rules require the end IP to be 192.168.1.255 to span the whole subnet.
Visual reference
Go deeper
Related to this question
Key term
Azure SQL Firewall Rules
Azure SQL Firewall Rules are security settings that control which IP addresses or Azure services are allowed to connect to a SQL database hosted in Microsoft Azure.
Key term
Azure SQL Performance Tuning
Azure SQL Performance Tuning is the process of optimizing the speed and efficiency of queries and database operations in Microsoft Azure SQL Database or SQL Managed Instance to reduce latency and improve throughput.
About these practice questions
This DP-300 question is part of Courseiva's 574-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DP-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-300 exam.