DP-300 Implement a secure environment Practice Question
You are the DBA for an Azure SQL Database that stores sensitive financial data. The security team requires that all user activity on the database be audited, and audit logs must be retained for 90 days. You need to configure auditing with minimal effort. What should you do?
⚠ Common exam trap
Test-takers frequently confuse Azure Monitor diagnostic settings with SQL auditing; while both can send logs, only SQL auditing is designed to capture all database activity for compliance with configurable retention.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable Azure SQL Database auditing and configure it to write logs to an Azure Storage account with a retention period of 90 days.
Enabling Azure SQL Database auditing and directing logs to Azure Storage with a 90-day retention period is the correct approach because it is a built-in feature that captures all user activity and meets the retention requirement with minimal configuration. The other options either are not supported in Azure SQL Database, require more manual effort, or do not provide the required audit scope.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use SQL Server Extended Events to capture all statements and store the files in Azure Blob Storage.
Why it's wrong here
Extended Events is available in Azure SQL Database but requires manual setup and management of event sessions and file targets. It is not the built-in auditing feature and does not provide the same compliance-oriented audit logs with retention settings. It is more complex and not the minimal-effort solution.
- ✓
Enable Azure SQL Database auditing and configure it to write logs to an Azure Storage account with a retention period of 90 days.
Why this is correct
Azure SQL Database auditing can be enabled at the server or database level and configured to write to Azure Storage, Log Analytics, or Event Hubs. Setting retention to 90 days in the storage account meets the requirement. This is the simplest way to audit all user activity and retain logs for the specified period.
- ✗
Enable Azure Monitor diagnostic settings on the database and send logs to a Log Analytics workspace with 90-day retention.
Why it's wrong here
Azure Monitor diagnostic settings can route logs, but for Azure SQL Database, auditing is configured through the SQL auditing feature, not directly via diagnostic settings. While diagnostic settings can send some logs, they do not capture all audit events required, and retention is managed in Log Analytics, not the audit configuration.
- ✗
Create a SQL Server Audit specification on the database and write to the Windows Application log.
Why it's wrong here
Azure SQL Database does not support writing SQL Server Audit output to the Windows Application log; that is an on-premises SQL Server option. Azure SQL Database has its own auditing feature that integrates with Azure Storage, Log Analytics, or Event Hubs, so this approach is not applicable.
Go deeper
Related to this question
Learn chapter
Securing Data at Rest and in Transit
Key term
Azure SQL Auditing
Azure SQL Auditing is a feature that tracks and records database events, such as data changes and logins, and writes them to an audit log for security monitoring and compliance.
Key term
Azure SQL Performance Tuning
Azure SQL Performance Tuning is the process of optimizing the speed and efficiency of queries and database operations in Microsoft Azure SQL Database or SQL Managed Instance to reduce latency and improve throughput.
About these practice questions
Courseiva writes every DP-300 question from scratch — 574 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This DP-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-300 exam.