DP-300 Plan and implement data platform resources Practice Question
You are configuring security for an Azure SQL Database. You need to ensure that only traffic from a specific virtual network and a specific set of public IP addresses can connect to the database. Which two features should you enable?
⚠ Common exam trap
Many candidates confuse network-level controls (firewall rules, service endpoints) with identity/security monitoring features (Entra ID, ATP), leading them to pick options that address authentication or threat detection instead of network access restrictions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
VNet service endpoints and firewall rules
To restrict access to an Azure SQL Database to traffic from a specific virtual network and a specific set of public IP addresses, you need to combine VNet service endpoints with firewall rules. VNet service endpoints allow you to restrict inbound traffic from a specific subnet in a virtual network, while firewall rules (IP-based) allow you to specify allowed public IP address ranges. Together, they provide a layered network security approach that meets the requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Entra ID authentication and firewall rules
Why it's wrong here
Microsoft Entra ID authentication governs identity, not network origin, and firewall rules alone cannot restrict traffic to a virtual network. It is tempting because both are core database security controls, but the scenario needs VNet service endpoints or a private endpoint plus firewall rules covering the public IP addresses.
- ✓
VNet service endpoints and firewall rules
Why this is correct
VNet service endpoints restrict connectivity to the specified subnet, while firewall rules permit the named public IP addresses. Together they satisfy the requirement that only that virtual network and those public IPs can reach the Azure SQL Database.
- ✗
Advanced Threat Protection and VNet service endpoints
Why it's wrong here
Advanced Threat Protection alerts on suspicious activity rather than filtering connections; VNet service endpoints restrict the virtual network side only. It is tempting because both sound security-related, but the public IP address requirement demands firewall rules, and traffic filtering needs service endpoints or a private endpoint.
- ✗
Private endpoint and VNet service endpoints
Why it's wrong here
Private endpoint and VNet service endpoints both secure the virtual network path, so the public IP address requirement is unmet. It is tempting because each restricts network access, but they are alternative mechanisms for the same axis; the scenario needs one of them paired with firewall rules for the public addresses.
Visual reference
Go deeper
Related to this question
Learn chapter
Managing Identity and Access for Azure SQL
Key term
Azure SQL Performance Tuning
Azure SQL Performance Tuning is the process of optimizing the speed and efficiency of queries and database operations in Microsoft Azure SQL Database or SQL Managed Instance to reduce latency and improve throughput.
About these practice questions
Courseiva writes every DP-300 question from scratch — 574 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DP-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-300 exam.