DP-300 Implement a secure environment Practice Question
You manage an Azure SQL Database server that hosts multiple databases. The security policy requires that all connections to the server use a minimum TLS version of 1.2 and that the setting applies to all databases on the server. What should you configure?
⚠ Common exam trap
Candidates often confuse the 'Enforce SSL connection' setting with the 'Minimum TLS version' setting; the former only requires encryption, while the latter actually enforces a specific TLS version.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Set the Minimum TLS version to 1.2 in the server's networking properties in the Azure portal.
The minimum TLS version is a server-level networking setting in Azure SQL Database. Configuring it to 1.2 in the server's networking properties ensures that all connections to all databases on that server must use TLS 1.2 or higher. Firewall rules, connection policies, and client-side settings do not enforce the minimum TLS version server-wide.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Set the Minimum TLS version to 1.2 in the server's Transact-SQL firewall settings.
Why it's wrong here
Transact-SQL firewall settings control which client IP addresses can connect, not the TLS version. The minimum TLS version is a separate server-level property configured through the Azure portal, PowerShell, or CLI, so this setting would not enforce TLS 1.2 for connections.
- ✓
Set the Minimum TLS version to 1.2 in the server's networking properties in the Azure portal.
Why this is correct
The minimum TLS version is a server-level networking property in Azure SQL Database. Setting it to 1.2 in the Azure portal (or via PowerShell/CLI) enforces that all connections to every database on that server use at least TLS 1.2, satisfying the security policy with a single configuration.
- ✗
Enable 'Enforce SSL connection' on the server and set the client driver to TLS 1.2.
Why it's wrong here
Enforce SSL connection simply requires encryption but does not specify a minimum TLS version; it may still allow TLS 1.0 or 1.1. Setting the client driver to TLS 1.2 does not prevent other clients from using older versions, so this combination fails to enforce the policy server-wide.
- ✗
Configure the database's connection policy to 'Proxy' and enable TLS 1.2 in the connection string.
Why it's wrong here
The connection policy (Proxy vs. Redirect) affects how connections are routed, not the minimum TLS version. Specifying TLS 1.2 in a connection string is a client-side preference and does not enforce server-side rejection of older TLS versions, so it does not meet the requirement.
Go deeper
Related to this question
Learn chapter
Migrating On-Premises Databases to Azure
Key term
Azure SQL Performance Tuning
Azure SQL Performance Tuning is the process of optimizing the speed and efficiency of queries and database operations in Microsoft Azure SQL Database or SQL Managed Instance to reduce latency and improve throughput.
About these practice questions
Courseiva writes every DP-300 question from scratch — 574 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This DP-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-300 exam.