Courseiva

DP-300 Implement a secure environment Practice Question

You are the Azure SQL Database administrator for a financial services company. The compliance team requires that all data in transit between the application tier and Azure SQL Database be encrypted, and that the server enforce a minimum TLS version of 1.2. The application servers run Windows Server 2019 and use the Microsoft.Data.SqlClient provider. You need to configure the server so that only TLS 1.2 connections are accepted. What should you do?

⚠ Common exam trap

The trap here is assuming that enabling TDE or a private endpoint automatically raises the minimum TLS version, when only the server-level Minimum TLS version setting enforces it.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Set the Minimum TLS version to 1.2 on the Azure SQL logical server's networking settings.

Azure SQL Database encrypts connections by default, but the minimum TLS version accepted by the gateway is controlled by the logical server's Minimum TLS version setting. Raising it to 1.2 causes the gateway to refuse any connection that negotiates a lower version, which is exactly what the compliance requirement demands. Firewall rules, private endpoints, and TDE address different concerns.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure a private endpoint for the Azure SQL Database and disable public network access.

    Why it's wrong here

    A private endpoint moves traffic onto a private IP path within the virtual network, but it does not by itself enforce a minimum TLS version. Clients can still negotiate older TLS versions over the private link unless the server's Minimum TLS version is explicitly raised, so this alone does not meet the stated requirement.

  • ✗

    Enable Transparent Data Encryption (TDE) on the database with a customer-managed key.

    Why it's wrong here

    TDE encrypts data at rest in the data and log files, not data in transit. A customer-managed key only changes who controls the key protecting the database files. It has no effect on which TLS version the gateway negotiates with the application servers, so it does not meet the in-transit encryption requirement.

  • ✗

    Add a firewall rule that allows only the application servers' IP addresses.

    Why it's wrong here

    Firewall rules restrict which source IP addresses may reach the server, but they do not inspect or enforce the TLS version of the connection. An allowed client could still connect with TLS 1.0 or 1.1, so this configuration does not satisfy the compliance requirement for a minimum TLS 1.2.

  • ✓

    Set the Minimum TLS version to 1.2 on the Azure SQL logical server's networking settings.

    Why this is correct

    The Azure SQL logical server exposes a Minimum TLS version setting under Networking in the Azure portal and via the minimalTlsVersion property in the Microsoft.Sql/servers resource. Setting it to 1.2 causes the gateway to reject connections negotiated below TLS 1.2, which directly satisfies the compliance requirement for the application tier.

Go deeper

Related to this question

About these practice questions

This DP-300 question is part of Courseiva's 574-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This DP-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-300 exam.