Courseiva

DP-300 Plan and implement data platform resources Practice Question

You are deploying an Azure SQL Database and need to enforce that all connections to the database use encrypted channels and that the server presents a specific certificate that the client validates. You also need to ensure that the database cannot be accessed from the public internet except through a private endpoint. Which two actions should you perform? (Choose two.)

⚠ Common exam trap

The trap here is assuming that Transparent Data Encryption protects data in transit, when TDE only encrypts data at rest and has no effect on the TLS channel or certificate validation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Set the Encrypt connection setting to mandatory in the connection string and use TrustServerCertificate=False with a trusted root certificate.

A private endpoint with public network access disabled ensures the logical server is reachable only through a private IP address inside a virtual network, removing exposure to the public internet. Requiring encryption in the connection string and setting TrustServerCertificate to false forces TLS and makes the client validate the server certificate against a trusted root. Together these actions satisfy both the private connectivity and certificate-validation requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable Transparent Data Encryption (TDE) with a customer-managed key stored in Azure Key Vault.

    Why it's wrong here

    TDE encrypts data at rest, including backups and log files, but it does not encrypt network traffic between the client and the database. Customer-managed keys add control over the encryption key but do not affect connection encryption or certificate validation. This action addresses data-at-rest protection, not the in-transit encryption and certificate validation required by the scenario.

  • ✗

    Enable Always Encrypted with secure enclaves for the columns that contain sensitive data.

    Why it's wrong here

    Always Encrypted protects sensitive column data from the database engine and administrators, and secure enclaves allow richer operations on encrypted data. It does not encrypt the network channel or require the client to validate a server certificate. This feature addresses data confidentiality within the database, not the transport security and private endpoint requirements of the scenario.

  • ✓

    Set the Encrypt connection setting to mandatory in the connection string and use TrustServerCertificate=False with a trusted root certificate.

    Why this is correct

    Requiring encryption in the connection string forces the client to use TLS, and setting TrustServerCertificate to false makes the client validate the server certificate against a trusted root. This satisfies the requirement that connections use encrypted channels and that the client validates a specific certificate. It works with both public and private endpoints but is essential for certificate validation.

  • ✗

    Configure an Azure SQL Database firewall rule that allows only the application's public IP address.

    Why it's wrong here

    A firewall rule restricts which public IP addresses can connect, but the database still has a public endpoint and traffic still traverses the public internet. It does not provide a private endpoint or disable public access. This option also does not enforce certificate validation on the client. It is a network access control, not the private connectivity required here.

  • ✓

    Configure the Azure SQL Database server to use a private endpoint and disable public network access.

    Why this is correct

    Creating a private endpoint places the logical server on a private IP address inside a virtual network, and disabling public network access removes the public endpoint. This ensures the database is reachable only through the private endpoint and not from the public internet, which is one of the stated requirements. It also supports the use of private DNS for name resolution.

About these practice questions

This DP-300 question is part of Courseiva's 574-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This DP-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-300 exam.