DP-300 Configure and manage automation of tasks Practice Question
You need to automate the deployment of an Azure SQL Database using Infrastructure as Code. The deployment should include the database, firewall rules, and threat detection settings. Which tool should you use?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Azure Resource Manager templates
Azure Resource Manager (ARM) templates are the native IaC for Azure. Azure Automation runbooks can deploy but are not declarative. Azure CLI can script deployments but is imperative. Azure Policy is for governance, not deployment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Azure CLI scripts
Why it's wrong here
Azure CLI scripts issue imperative commands; they do not maintain declarative desired-state templates, so firewall and threat detection settings drift without idempotent redeployment. Azure CLI suits ad-hoc or pipeline scripting, whereas Bicep or ARM templates express the full resource configuration declaratively.
- ✗
Azure Automation runbooks
Why it's wrong here
Azure Automation runbooks execute imperative scripts or PowerShell against Azure, so they lack the declarative template that defines the database, firewall rules and threat detection settings as one deployable unit. Runbooks suit scheduled operational tasks such as starting databases, not repeatable Infrastructure as Code provisioning.
- ✗
Azure Policy
Why it's wrong here
Azure Policy enforces and audits resource configuration against governance rules; it cannot declare and deploy a database, firewall rules and threat detection settings as a template. It is tempting because it governs Azure SQL security settings at scale, but that is compliance enforcement after deployment, not Infrastructure as Code provisioning.
- ✓
Azure Resource Manager templates
Why this is correct
ARM templates declaratively define the Azure SQL Database, firewall rules, and threat detection settings in one deployment, satisfying the Infrastructure as Code requirement. They natively support all three resource types without custom scripting or extra tooling.
Go deeper
Related to this question
Learn chapter
Configuring Automation Tasks for Database Administration
Key term
Azure SQL Threat Detection
Azure SQL Threat Detection is a built-in security feature that continuously monitors your Azure SQL database for suspicious activities and sends alerts when potential threats are found.
Key term
Azure SQL Performance Tuning
Azure SQL Performance Tuning is the process of optimizing the speed and efficiency of queries and database operations in Microsoft Azure SQL Database or SQL Managed Instance to reduce latency and improve throughput.
About these practice questions
Courseiva writes every DP-300 question from scratch — 574 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DP-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-300 exam.