Courseiva

DP-300 Implement a secure environment Practice Question

Exhibit

Refer to the exhibit.

```json
{
  "properties": {
    "startIPAddress": "10.0.0.0",
    "endIPAddress": "10.0.0.255"
  }
}
```

You are reviewing a JSON representation of an Azure SQL Database firewall rule. What is the effect of this rule?

⚠ Common exam trap

Test-takers frequently confuse the inclusive range behavior with a single IP or assume that a range implies blocking, when in fact Azure SQL Database firewall only supports allow rules and the range is inclusive of both endpoints.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Allows all IP addresses from 10.0.0.0 to 10.0.0.255.

The JSON representation of the Azure SQL Database firewall rule with startIpAddress '10.0.0.0' and endIpAddress '10.0.0.255' defines a range that allows all IP addresses from 10.0.0.0 to 10.0.0.255 inclusive. Azure SQL Database firewall rules use inclusive IP range matching, so any client with an IP in that range is permitted to connect, provided the rule is enabled.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Blocks all IP addresses from 10.0.0.0 to 10.0.0.255.

    Why it's wrong here

    A firewall rule's start_ip_address and end_ip_address define an allowed range, not a denied one; no rule ever blocks traffic in Azure SQL Database. This option is tempting because the range notation resembles a subnet mask, but the rule would permit 10.0.0.0–10.0.0.255, not block it.

  • ✗

    Allows all IP addresses except 10.0.0.0 to 10.0.0.255.

    Why it's wrong here

    Azure SQL Database firewall rules are allowlists: each rule permits the specified start_ip_address to end_ip_address range, and traffic outside all rules is denied. Nothing can express "all except this range". The option tempts because deny-by-exception logic exists in network ACLs, but not in this firewall.

  • ✓

    Allows all IP addresses from 10.0.0.0 to 10.0.0.255.

    Why this is correct

    The rule's start and end addresses define an inclusive contiguous range, so every address from 10.0.0.0 through 10.0.0.255 is permitted. Azure SQL Database evaluates the client's source IP against this span, meaning the entire /24 subnet can connect rather than one host.

  • ✗

    Allows only the IP address 10.0.0.0.

    Why it's wrong here

    A firewall rule specifying 10.0.0.0 without a range covers only that single address, not a subnet. It is tempting because the notation resembles a network prefix, and a rule with start and end IPs of 10.0.0.0 would be correct to permit only that one host.

About these practice questions

This DP-300 question is part of Courseiva's 574-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DP-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-300 exam.