Courseiva

DP-300 Configure and manage automation of tasks Practice Question

You need to automate the deployment of Azure SQL Database logical servers and databases using Bicep. What is the best practice for storing the administrative password securely?

⚠ Common exam trap

Watch out — candidates often think environment variables or generated passwords are acceptable for automation, but the DP-300 exam specifically tests the secure secret management pattern using Azure Key Vault with Bicep's `getSecret` function, not just any method of hiding the password.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Reference the password from Azure Key Vault using the getSecret function

Azure Key Vault is the recommended secure storage for secrets like administrative passwords in Azure deployments. Using the `getSecret` function in Bicep allows you to reference a secret from Key Vault at deployment time without exposing the password in the Bicep file or deployment logs, aligning with Azure security best practices and the principle of least privilege.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Reference the password from Azure Key Vault using the getSecret function

    Why this is correct

    Referencing the password via Key Vault's getSecret function keeps the credential out of the Bicep template and its deployment history, satisfying the requirement to store the administrative password securely. The secret is resolved at deployment time from Key Vault, so plaintext never appears in source control or ARM deployment records.

  • ✗

    Use the adminPassword property with a generated password

    Why it's wrong here

    A generated password still lands in the template or parameter file unless routed through Key Vault, so the secret is exposed at deployment time and cannot be rotated cleanly. It tempts because generating credentials avoids hardcoding a human-chosen value, which suits ephemeral non-production environments.

  • ✗

    Use an environment variable in the deployment script

    Why it's wrong here

    Environment variables are readable by any process on the deployment host and are not encrypted at rest, so the password leaks outside Key Vault's audit boundary. It tempts because environment variables keep secrets out of source control, which works for local scripted deployments lacking a vault.

  • ✗

    Store the password as a plain text parameter in the Bicep file

    Why it's wrong here

    Plain-text parameters persist the password in source control and deployment history, exposing credentials to anyone with repository or portal read access. It tempts because inline parameters are the quickest way to make a Bicep template self-contained for throwaway test deployments where no real secret exists.

About these practice questions

This DP-300 question is part of Courseiva's 574-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DP-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-300 exam.