Courseiva

DP-300 Practice Question: Monitor, configure, and optimize database resources

Exhibit

Refer to the exhibit.

```json
{
  "properties": {
    "state": "Disabled",
    "emailAccountAdmins": true,
    "emailAddresses": ["dba@contoso.com"],
    "disabledAlerts": ["SqlInjection", "SqlInjectionVulnerability"],
    "retentionDays": 30
  }
}
```

You are reviewing an Azure SQL Database server's vulnerability assessment settings. The exhibit shows the current configuration. A recent security audit requires that vulnerability assessment scans be enabled and that results be retained for at least 90 days. What should you do?

⚠ Common exam trap

DP-300 often tests the distinction between enabling a feature and configuring its retention, and candidates may mistakenly think that changing retention alone or adjusting notifications is sufficient without enabling the feature.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Change state to Enabled and set retentionDays to 90.

The requirement is to enable vulnerability assessment scans and retain results for at least 90 days. Option C correctly sets the state to Enabled (turning on the scans) and sets retentionDays to 90 (meeting the retention requirement). The other options either leave the state disabled or address unrelated settings like email notifications or alert suppression.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Add additional email addresses to ensure notification.

    Why it's wrong here

    Email addresses only determine who receives scan notifications; they neither enable scanning nor extend result retention. It is tempting because notifications support security operations, but the audit requires the assessment state to be Enabled and retentionDays set to at least 90.

  • ✗

    Change retentionDays to 90 and keep the state as Disabled.

    Why it's wrong here

    Retention only applies once scanning is active, so leaving state as Disabled still produces no assessment results to retain. It is tempting because retentionDays is the visible retention control, but the audit also demands scans be enabled, which this option omits.

  • ✓

    Change state to Enabled and set retentionDays to 90.

    Why this is correct

    Vulnerability assessment is inactive until its state is Enabled, and the audit mandates 90-day result retention. Setting retentionDays to 90 meets that minimum while enabling scans satisfies the first requirement, so both properties must change together on the server's configuration.

  • ✗

    Remove the disabledAlerts entries to enable all alerts.

    Why it's wrong here

    disabledAlerts controls which alert types fire, not whether vulnerability assessment scans run or how long results persist. It is tempting because alerts relate to security monitoring, but the audit's requirements map to the assessment's state and retentionDays settings instead.

About these practice questions

One of 574 original DP-300 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This DP-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-300 exam.