DP-300 Configure and manage automation of tasks Practice Question
You need to automate the deployment of Azure SQL Database with a specific configuration across multiple environments (dev, test, prod). The deployment must include firewall rules, auditing settings, and threat detection policies. Which THREE tools can be used to implement this automation?
⚠ Common exam trap
The trap is selecting tools that are database management or migration focused (Azure Data Studio, Azure Migrate) instead of infrastructure automation tools; candidates must recognize that automation of deployment requires IaC or CLI/PowerShell, not client query tools.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
ARM templates with Bicep
ARM templates with Bicep (A) are correct because Bicep is a declarative IaC language that transpiles to ARM JSON, allowing you to define Azure SQL Database resources, firewall rules, auditing settings, and threat detection policies as code and deploy them idempotently across dev, test, and prod. Azure PowerShell (C) is correct because cmdlets such as New-AzSqlServerFirewallRule, Set-AzSqlServerAudit, and Set-AzSqlDatabaseThreatDetectionPolicy let you script the full deployment and configuration of Azure SQL Database programmatically. Azure CLI (E) is correct because commands like az sql server firewall-rule create, az sql server audit-policy update, and az sql db threat-policy update provide cross-platform scripting for the same automation. Azure Migrate (B) is not correct because it is a discovery, assessment, and migration service for on-premises workloads, not a deployment automation tool. Azure Data Studio (D) is not correct because it is an interactive query and management client, not an automation or infrastructure-as-code tool for repeatable multi-environment deployments.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
ARM templates with Bicep
Why this is correct
Bicep is a declarative DSL that transpiles to ARM templates, letting you define the database, firewall rules, auditing, and threat detection policies once and redeploy identically across dev, test, and prod. Parameter files handle per-environment differences.
- ✗
Azure Migrate
Why it's wrong here
Azure Migrate discovers, assesses and migrates on-premises workloads to Azure; it does not deploy new Azure SQL Database configurations or apply firewall, auditing and threat detection policies. It is tempting because it automates Azure migration projects, but greenfield multi-environment provisioning requires ARM templates, Bicep or Terraform.
- ✓
Azure PowerShell
Why this is correct
Azure PowerShell satisfies the repeatable, multi-environment deployment constraint by provisioning Azure SQL Database declaratively through cmdlets such as New-AzSqlServerFirewallRule, Set-AzSqlServerAudit and threat detection policy cmdlets, all scriptable and parameterised per environment. It manages the full resource configuration, including firewall rules, auditing and threat detection, in one automated run.
- ✗
Azure Data Studio
Why it's wrong here
Azure Data Studio is an interactive query and notebook client, not a deployment automation engine; it cannot declaratively provision databases, firewall rules, auditing or threat detection across environments. It is tempting because notebooks can run scripts, but repeatable infrastructure deployment needs ARM templates, Bicep or Terraform.
- ✓
Azure CLI
Why this is correct
Azure CLI satisfies the multi-environment automation constraint by scripting `az sql server` and `az sql db` commands, including firewall rules, auditing, and threat detection policies, then parameterising them per environment. Its cross-platform, idempotent command set integrates into pipelines, so dev, test, and prod deployments remain consistent and repeatable without portal interaction.
Go deeper
Related to this question
Learn chapter
Managing Environment Configurations and Resource Governance
Key term
Azure SQL Threat Detection
Azure SQL Threat Detection is a built-in security feature that continuously monitors your Azure SQL database for suspicious activities and sends alerts when potential threats are found.
Key term
Azure SQL Performance Tuning
Azure SQL Performance Tuning is the process of optimizing the speed and efficiency of queries and database operations in Microsoft Azure SQL Database or SQL Managed Instance to reduce latency and improve throughput.
About these practice questions
Courseiva writes every DP-300 question from scratch — 574 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This DP-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-300 exam.