DP-300 Implement a secure environment Practice Question
You manage an Azure SQL Database. A security review finds that an application service principal is connecting with a SQL login that has db_owner membership, and that the login's password has not changed in two years. You must reduce the standing privilege and eliminate the long-lived password while keeping the application working. What should you do?
⚠ Common exam trap
The trap here is believing that moving a password into Key Vault or rotating it satisfies a no-long-lived-password requirement, when the password itself still exists and the excessive role membership is untouched.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a contained database user mapped to the service principal's Microsoft Entra identity, grant it only the required permissions, and remove the SQL login
Replacing the password-based SQL login with a contained database user mapped to the service principal removes the long-lived secret and lets you grant only the permissions the application actually needs. Rotating a password or renaming the role leaves both problems intact, and merely enabling directory authentication without removing the login does not close the insecure path.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Rotate the SQL login password and move it into Azure Key Vault, leaving db_owner membership unchanged
Why it's wrong here
Rotating the password addresses the age of the credential but leaves a password-based secret in play and keeps the excessive db_owner membership. The standing privilege remains, so a compromise of the application host still yields full control of the database. This does not reduce privilege or eliminate the long-lived password.
- ✗
Enable Microsoft Entra authentication on the server and keep the SQL login as a fallback for the application
Why it's wrong here
Enabling directory authentication adds a new method but does not remove the existing SQL login or its db_owner membership, so the long-lived password and excessive privilege persist. Keeping the login as a fallback means the insecure path stays active. This does not meet the requirement to eliminate the credential and reduce privilege.
- ✓
Create a contained database user mapped to the service principal's Microsoft Entra identity, grant it only the required permissions, and remove the SQL login
Why this is correct
A contained database user mapped to the service principal authenticates through Microsoft Entra ID, so no password exists to rotate or leak. Granting only the permissions the application needs removes the db_owner standing privilege. Removing the old SQL login closes the credential path entirely, satisfying both the least-privilege and no-long-lived-password requirements.
- ✗
Add the service principal to a custom database role with db_owner and enforce a password policy on the login
Why it's wrong here
Placing the principal in a role that carries db_owner preserves the same excessive rights under a different name, and a password policy only hardens the existing password rather than removing it. The long-lived credential and the over-privileged access both remain, so the security findings are unresolved.
Go deeper
Related to this question
About these practice questions
This DP-300 question is part of Courseiva's 574-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This DP-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-300 exam.