Courseiva

DP-300 Implement a secure environment Practice Question

You are the DBA for an Azure SQL Database that stores sensitive financial data. The security team requires that all user activity on the database be audited, and audit logs must be retained for 90 days. You need to configure auditing with minimal effort. What should you do?

⚠ Common exam trap

Test-takers frequently confuse Azure Monitor diagnostic settings with SQL auditing; while both can send logs, only SQL auditing is designed to capture all database activity for compliance with configurable retention.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable Azure SQL Database auditing and configure it to write logs to an Azure Storage account with a retention period of 90 days.

Enabling Azure SQL Database auditing and directing logs to Azure Storage with a 90-day retention period is the correct approach because it is a built-in feature that captures all user activity and meets the retention requirement with minimal configuration. The other options either are not supported in Azure SQL Database, require more manual effort, or do not provide the required audit scope.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use SQL Server Extended Events to capture all statements and store the files in Azure Blob Storage.

    Why it's wrong here

    Extended Events is available in Azure SQL Database but requires manual setup and management of event sessions and file targets. It is not the built-in auditing feature and does not provide the same compliance-oriented audit logs with retention settings. It is more complex and not the minimal-effort solution.

  • ✓

    Enable Azure SQL Database auditing and configure it to write logs to an Azure Storage account with a retention period of 90 days.

    Why this is correct

    Azure SQL Database auditing can be enabled at the server or database level and configured to write to Azure Storage, Log Analytics, or Event Hubs. Setting retention to 90 days in the storage account meets the requirement. This is the simplest way to audit all user activity and retain logs for the specified period.

  • ✗

    Enable Azure Monitor diagnostic settings on the database and send logs to a Log Analytics workspace with 90-day retention.

    Why it's wrong here

    Azure Monitor diagnostic settings can route logs, but for Azure SQL Database, auditing is configured through the SQL auditing feature, not directly via diagnostic settings. While diagnostic settings can send some logs, they do not capture all audit events required, and retention is managed in Log Analytics, not the audit configuration.

  • ✗

    Create a SQL Server Audit specification on the database and write to the Windows Application log.

    Why it's wrong here

    Azure SQL Database does not support writing SQL Server Audit output to the Windows Application log; that is an on-premises SQL Server option. Azure SQL Database has its own auditing feature that integrates with Azure Storage, Log Analytics, or Event Hubs, so this approach is not applicable.

Go deeper

Related to this question

About these practice questions

Courseiva writes every DP-300 question from scratch — 574 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This DP-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-300 exam.