Courseiva

DP-300 Implement a secure environment Practice Question

You need to configure Azure SQL Database to allow connections only from Azure services and from a specific on-premises IP range. Which firewall rule configuration should you apply at the server level?

⚠ Common exam trap

A common mix-up: candidates think 'Allow Azure Services' must be OFF to secure the database, but they miss that the requirement explicitly asks to allow connections from Azure services, making ON necessary, and then they forget to add the on-premises IP rule separately.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Set 'Allow Azure Services and resources to access this server' to ON and add a firewall rule for the on-premises IP range.

Enabling 'Allow Azure Services and resources to access this server' permits connections from all Azure services (including those from other subscriptions) by adding a special firewall rule that allows Azure IP ranges. Adding a separate firewall rule for the specific on-premises IP range then restricts non-Azure external traffic to only that range. This combination meets the requirement to allow only Azure services and the specified on-premises range.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a private endpoint for the server.

    Why it's wrong here

    A private endpoint gives the server a private IP inside a VNet, which does not satisfy the requirement to permit Azure services plus one on-premises IP range at the server level. It is tempting for isolating PaaS traffic, and would be correct if all clients connected privately over ExpressRoute or VPN.

  • ✗

    Create a virtual network service endpoint and add a VNet firewall rule.

    Why it's wrong here

    A virtual network service endpoint restricts traffic to a specific subnet, not to an on-premises IP range, and does not cover Azure services generally. It is tempting because it hardens connectivity, and would be correct if only workloads in one designated VNet subnet needed access.

  • ✓

    Set 'Allow Azure Services and resources to access this server' to ON and add a firewall rule for the on-premises IP range.

    Why this is correct

    Enabling 'Allow Azure Services and resources to access this server' permits the Azure-internal 0.0.0.0 virtual gateway address, satisfying the Azure-services constraint, while an explicit server-level firewall rule scoped to the on-premises range restricts external access to that range only. Together they meet both requirements without exposing the server publicly.

  • ✗

    Set 'Allow Azure Services and resources to access this server' to OFF and add a firewall rule for the on-premises IP range.

    Why it's wrong here

    Turning off Azure services access blocks the Azure-services traffic the scenario requires, leaving only the on-premises range. It is tempting as a hardening measure, and would be correct if the requirement were to permit solely the on-premises IP range and no Azure-hosted services.

About these practice questions

Courseiva writes every DP-300 question from scratch — 574 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DP-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-300 exam.