Courseiva

DP-300 Implement a secure environment Practice Question

You need to ensure that all users accessing Azure SQL Database from outside the corporate network are required to use multi-factor authentication (MFA). What should you configure?

⚠ Common exam trap

Candidates often confuse Azure Policy (which governs resource configuration compliance) with Conditional Access (which governs user authentication and access conditions), leading candidates to choose Azure Policy when only Conditional Access can enforce MFA at the sign-in level.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure a Conditional Access policy in Microsoft Entra ID.

Conditional Access policies in Microsoft Entra ID (formerly Azure AD) allow you to enforce MFA based on network location, device state, or risk level. By configuring a policy that targets the Azure SQL Database application and requires MFA for all access from outside the corporate network, you meet the requirement without altering the database or server configuration.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable Azure RBAC for the SQL server.

    Why it's wrong here

    Azure RBAC governs authorisation to management and data-plane resources; it does not perform interactive authentication, so MFA cannot be demanded through role assignments. It would be correct when scoping who may manage or query a server after identity is already established.

  • ✓

    Configure a Conditional Access policy in Microsoft Entra ID.

    Why this is correct

    Conditional Access evaluates sign-in conditions and enforces authentication strength, so a policy targeting users outside the corporate network can require MFA. This satisfies the constraint of enforcing MFA specifically for external access, which SQL firewall rules alone cannot do.

  • ✗

    Create an Azure Policy to require MFA.

    Why it's wrong here

    Azure Policy audits and enforces resource configuration, not user sign-in behaviour, so it cannot require MFA at connection time. It is tempting as a governance tool, but it is correct when restricting which resource properties, such as allowed SKUs or regions, may be deployed.

  • ✗

    Turn on Transparent Data Encryption (TDE).

    Why it's wrong here

    TDE encrypts data at rest and has no bearing on authentication, so it cannot enforce MFA for external connections. It is tempting as a security control, but it is the correct choice when the requirement is protecting database files and backups from unauthorised physical access.

About these practice questions

Courseiva writes every DP-300 question from scratch — 574 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DP-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-300 exam.