DP-300 Implement a secure environment Practice Question
You have an Azure SQL Database that needs to be accessed by an application running on an Azure VM. The VM is in a different subscription. You want to minimize administrative overhead and ensure secure connectivity without exposing the database to the public internet. What should you do?
⚠ Common exam trap
Many candidates confuse VNet service endpoints with private endpoints, assuming service endpoints provide the same level of isolation, but service endpoints still rely on the public endpoint of Azure SQL and do not remove public exposure.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a private endpoint for the SQL Database in the VM's VNet.
A private endpoint assigns the Azure SQL Database a private IP address from the VM's VNet, enabling secure connectivity over the Microsoft backbone without exposing the database to the public internet. This minimizes administrative overhead as it does not require VPN gateways or complex routing, and it works across subscriptions by linking the private endpoint to the VM's VNet.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Set up a site-to-site VPN between the VM's VNet and the SQL Database's VNet.
Why it's wrong here
A site-to-site VPN establishes secure connectivity between two virtual networks or an on-premises network and an Azure VNet. This option fails because Azure SQL Database is a platform-as-a-service (PaaS) offering, not a VNet itself, making direct site-to-site VPN peering to it technically incorrect and overly complex for this scenario. It is tempting as VPNs provide secure cross-network communication, and would be the correct choice if the requirement was to connect two separate Azure VNets (e.g., in different subscriptions) or an on-premises network to an Azure VNet.
- ✗
Use a VNet service endpoint for Azure SQL Database in the VM's VNet.
Why it's wrong here
VNet service endpoints for Azure SQL Database route traffic from a chosen subnet to the database over the Microsoft backbone, but the database's logical server still resolves to its public endpoint, which lacks a private IP address. Service endpoints also operate at the subnet level and are commonly scoped to a single subscription, requiring the VM's VNet to be in the same subscription as the SQL Database to apply. Because they do not assign a private IP to the database inside the VM's VNet, they fail to meet the requirement for private, cross-subscription access.
- ✓
Create a private endpoint for the SQL Database in the VM's VNet.
Why this is correct
A private endpoint provisions an Azure NIC with a private IP address from the VM's VNet to the SQL Database logical server, making the database appear as a native resource inside that VNet. Traffic between the VM and the database flows entirely over the Microsoft backbone and never traverses the public internet, even though the SQL Database can reside in a different subscription via Private Link. The private endpoint is deployed in the VM's VNet while the connection to the SQL Database resource is approved, enabling cross-subscription private connectivity with no public exposure.
- ✗
Configure a firewall rule to allow the VM's public IP address.
Why it's wrong here
Configuring an Azure SQL firewall rule to allow the VM's public IP address leaves the database's public endpoint enabled and accessible from the internet, creating an unnecessary attack surface. The VM's public IP must be static and rechecked whenever the VM or its Public IP configuration changes, since Azure public IPs can be lost if the resource is deallocated. This approach does not provide private connectivity; traffic crosses the internet and is protected only by the firewall rule, which is a far weaker security posture than a private endpoint.
Go deeper
Related to this question
About these practice questions
One of 574 original DP-300 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DP-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-300 exam.