Courseiva

DP-300 Implement a secure environment Practice Question

You are configuring security for an Azure SQL Database. The security team requires that all administrative actions on the server and databases are logged to an Azure Storage account, and that the logs are retained for 90 days. You need to configure auditing to meet these requirements with minimal effort. What should you do?

⚠ Common exam trap

The trap here is thinking that database-level auditing is needed for each database, but server-level auditing covers all databases and reduces administrative overhead.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable auditing at the server level and set the retention period to 90 days, targeting an Azure Storage account.

Server-level auditing with a 90-day retention targeting an Azure Storage account audits all databases on the server and meets the retention requirement. Database-level auditing would require per-database configuration, and using Log Analytics does not match the storage account requirement. Unlimited retention does not meet the 90-day specification.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Enable auditing at the server level and set the retention period to 90 days, targeting an Azure Storage account.

    Why this is correct

    Server-level auditing in Azure SQL Database automatically audits all databases on the server and can target an Azure Storage account. Setting the retention period to 90 days meets the retention requirement. This configuration applies to all current and future databases, minimizing administrative effort.

  • ✗

    Enable auditing at the server level and set the retention period to 0 (unlimited), targeting an Azure Storage account.

    Why it's wrong here

    Setting retention to 0 means unlimited retention, which does not meet the specific 90-day requirement and may retain data longer than necessary, potentially violating data retention policies. The requirement is a specific 90-day retention, so this setting is incorrect.

  • ✗

    Enable auditing at the server level and target an Azure Log Analytics workspace with a 90-day retention.

    Why it's wrong here

    Auditing can target Log Analytics, but the requirement specifies logging to an Azure Storage account. While Log Analytics offers querying capabilities, it does not meet the explicit storage account requirement and may incur additional cost and configuration.

  • ✗

    Enable auditing at the database level for each database and set the retention period to 90 days, targeting an Azure Storage account.

    Why it's wrong here

    Database-level auditing must be configured for each database individually, which increases administrative effort and may miss new databases. The requirement is to audit all administrative actions on the server and databases, so server-level auditing is more appropriate and less effort.

About these practice questions

One of 574 original DP-300 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This DP-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-300 exam.