DP-300 Implement a secure environment Practice Question
You are designing a secure environment for Azure SQL Database. Which TWO of the following are recommended practices for network security?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use Azure Private Link to connect to the database from a virtual network.
Option C is correct because Azure Private Link (Private Endpoint) provides a private IP address for the Azure SQL logical server inside your VNet, so traffic between the VNet and the database travels over the Microsoft backbone and never exposes the database to the public internet. Option D is correct because disabling public network access on the SQL server ensures the database accepts connections only through approved private paths (such as Private Endpoints) or explicitly permitted exceptions, eliminating the broad public endpoint attack surface. Option A is not recommended because 'Allow Azure services and resources to access this server' creates a firewall exception that permits traffic from any Azure service, which is overly permissive and not a targeted network security control. Option B is not recommended because VNet service endpoints still route traffic to the database's public endpoint and are generally considered less secure than Private Link, so cost should not drive that choice for a secure design. Option E is not recommended because allowing an entire organization IP range is a broad, IP-based rule that is weaker than private connectivity and can be bypassed if those addresses are compromised or spoofed.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable the 'Allow Azure services and resources to access this server' firewall setting.
Why it's wrong here
This setting opens the server's firewall to any Azure-hosted resource, including other tenants' services, rather than restricting access to known networks. It tempts because it quickly unblocks platform features such as Azure Data Factory, and it would suit a non-production server where connectivity matters more than isolation.
- ✗
Use VNet service endpoints instead of Private Link to reduce costs.
Why it's wrong here
Service endpoints still route traffic over Azure's public backbone and expose a public endpoint, whereas Private Link gives a private IP inside the VNet; cost is not the security criterion the question asks about. It tempts when budget constrains design, and it would be acceptable where Private Link is unavailable.
- ✓
Use Azure Private Link to connect to the database from a virtual network.
Why this is correct
Azure Private Link provisions a private endpoint inside the virtual network, so database traffic traverses the Microsoft backbone rather than the public internet. This removes public exposure, satisfying the network security requirement for private connectivity.
- ✓
Disable public network access on the SQL server.
Why this is correct
Disabling public network access removes the server's public endpoint entirely, forcing all connections through private endpoints or approved paths. This eliminates internet-facing attack surface, satisfying the requirement to restrict network exposure of the SQL server.
- ✗
Add firewall rules that allow all IP addresses from your organization's IP range.
Why it's wrong here
A broad organisation-wide IP range widens the attack surface and cannot enforce per-resource least privilege, unlike narrow rules or private endpoints. It tempts because it reduces administrative overhead for many users, and it would be reasonable for a small, static office network with no remote workforce.
Go deeper
Related to this question
Learn chapter
Managing Environment Configurations and Resource Governance
Key term
Azure SQL Performance Tuning
Azure SQL Performance Tuning is the process of optimizing the speed and efficiency of queries and database operations in Microsoft Azure SQL Database or SQL Managed Instance to reduce latency and improve throughput.
About these practice questions
This DP-300 question is part of Courseiva's 574-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DP-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-300 exam.