Courseiva

DP-300 Implement a secure environment Practice Question

You manage an Azure SQL Database. A security review finds that an application service principal is connecting with a SQL login that has db_owner membership, and that the login's password has not changed in two years. You must reduce the standing privilege and eliminate the long-lived password while keeping the application working. What should you do?

⚠ Common exam trap

The trap here is believing that moving a password into Key Vault or rotating it satisfies a no-long-lived-password requirement, when the password itself still exists and the excessive role membership is untouched.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a contained database user mapped to the service principal's Microsoft Entra identity, grant it only the required permissions, and remove the SQL login

Replacing the password-based SQL login with a contained database user mapped to the service principal removes the long-lived secret and lets you grant only the permissions the application actually needs. Rotating a password or renaming the role leaves both problems intact, and merely enabling directory authentication without removing the login does not close the insecure path.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Rotate the SQL login password and move it into Azure Key Vault, leaving db_owner membership unchanged

    Why it's wrong here

    Rotating the password addresses the age of the credential but leaves a password-based secret in play and keeps the excessive db_owner membership. The standing privilege remains, so a compromise of the application host still yields full control of the database. This does not reduce privilege or eliminate the long-lived password.

  • ✗

    Enable Microsoft Entra authentication on the server and keep the SQL login as a fallback for the application

    Why it's wrong here

    Enabling directory authentication adds a new method but does not remove the existing SQL login or its db_owner membership, so the long-lived password and excessive privilege persist. Keeping the login as a fallback means the insecure path stays active. This does not meet the requirement to eliminate the credential and reduce privilege.

  • ✓

    Create a contained database user mapped to the service principal's Microsoft Entra identity, grant it only the required permissions, and remove the SQL login

    Why this is correct

    A contained database user mapped to the service principal authenticates through Microsoft Entra ID, so no password exists to rotate or leak. Granting only the permissions the application needs removes the db_owner standing privilege. Removing the old SQL login closes the credential path entirely, satisfying both the least-privilege and no-long-lived-password requirements.

  • ✗

    Add the service principal to a custom database role with db_owner and enforce a password policy on the login

    Why it's wrong here

    Placing the principal in a role that carries db_owner preserves the same excessive rights under a different name, and a password policy only hardens the existing password rather than removing it. The long-lived credential and the over-privileged access both remain, so the security findings are unresolved.

About these practice questions

This DP-300 question is part of Courseiva's 574-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This DP-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-300 exam.