DP-300 Implement a secure environment Practice Question
You are the Azure SQL Database administrator for a financial services company. The compliance team requires that all data in transit between the application tier and Azure SQL Database be encrypted, and that the server enforce a minimum TLS version of 1.2. The application servers run Windows Server 2019 and use the Microsoft.Data.SqlClient provider. You need to configure the server so that only TLS 1.2 connections are accepted. What should you do?
⚠ Common exam trap
The trap here is assuming that enabling TDE or a private endpoint automatically raises the minimum TLS version, when only the server-level Minimum TLS version setting enforces it.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Set the Minimum TLS version to 1.2 on the Azure SQL logical server's networking settings.
Azure SQL Database encrypts connections by default, but the minimum TLS version accepted by the gateway is controlled by the logical server's Minimum TLS version setting. Raising it to 1.2 causes the gateway to refuse any connection that negotiates a lower version, which is exactly what the compliance requirement demands. Firewall rules, private endpoints, and TDE address different concerns.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure a private endpoint for the Azure SQL Database and disable public network access.
Why it's wrong here
A private endpoint moves traffic onto a private IP path within the virtual network, but it does not by itself enforce a minimum TLS version. Clients can still negotiate older TLS versions over the private link unless the server's Minimum TLS version is explicitly raised, so this alone does not meet the stated requirement.
- ✗
Enable Transparent Data Encryption (TDE) on the database with a customer-managed key.
Why it's wrong here
TDE encrypts data at rest in the data and log files, not data in transit. A customer-managed key only changes who controls the key protecting the database files. It has no effect on which TLS version the gateway negotiates with the application servers, so it does not meet the in-transit encryption requirement.
- ✗
Add a firewall rule that allows only the application servers' IP addresses.
Why it's wrong here
Firewall rules restrict which source IP addresses may reach the server, but they do not inspect or enforce the TLS version of the connection. An allowed client could still connect with TLS 1.0 or 1.1, so this configuration does not satisfy the compliance requirement for a minimum TLS 1.2.
- ✓
Set the Minimum TLS version to 1.2 on the Azure SQL logical server's networking settings.
Why this is correct
The Azure SQL logical server exposes a Minimum TLS version setting under Networking in the Azure portal and via the minimalTlsVersion property in the Microsoft.Sql/servers resource. Setting it to 1.2 causes the gateway to reject connections negotiated below TLS 1.2, which directly satisfies the compliance requirement for the application tier.
Go deeper
Related to this question
Learn chapter
Overview of Azure Data Platform Options
Key term
Azure SQL Performance Tuning
Azure SQL Performance Tuning is the process of optimizing the speed and efficiency of queries and database operations in Microsoft Azure SQL Database or SQL Managed Instance to reduce latency and improve throughput.
Key term
Transparent Data Encryption
Transparent Data Encryption is a security feature that automatically encrypts data written to a database and decrypts it when read, without requiring any changes to the application.
About these practice questions
This DP-300 question is part of Courseiva's 574-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This DP-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-300 exam.