DP-300 Implement a secure environment Practice Question
You need to protect Azure SQL Database from SQL injection attacks. Which THREE of the following measures should you implement?
⚠ Common exam trap
Test-takers frequently confuse data protection features like dynamic data masking or TDE with SQL injection prevention, when in fact they address entirely different threats (data exposure at query time vs. data at rest encryption).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable Microsoft Defender for SQL to detect and alert on SQL injection.
Option A is correct because Microsoft Defender for SQL provides advanced threat protection that specifically detects anomalous and potentially harmful activities such as SQL injection attempts against Azure SQL Database, generating alerts and recommendations. Option B is correct because parameterized queries and stored procedures ensure that user input is treated as data rather than executable SQL code, which is the fundamental application-level defense against SQL injection. Option D is correct because an Azure Web Application Firewall (WAF), for example on Application Gateway or Front Door, inspects HTTP/HTTPS traffic and blocks common injection patterns before they reach the application and database. Option C is not correct because dynamic data masking only obscures sensitive data in query results for unauthorized users; it does not prevent or detect SQL injection. Option E is not correct because Transparent Data Encryption protects data at rest by encrypting database files, but it does not stop SQL injection, which exploits the application's query logic rather than the storage layer.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enable Microsoft Defender for SQL to detect and alert on SQL injection.
Why this is correct
Microsoft Defender for SQL provides threat detection that identifies anomalous and injection-like query patterns against the database, raising alerts for investigation. It adds a detection layer that complements input validation and query parameterisation, forming part of a layered defence.
- ✓
Use parameterized queries or stored procedures in the application.
Why this is correct
Parameterised queries and stored procedures separate SQL code from user-supplied values, so injected input is treated as data rather than executable statements. This eliminates the primary injection vector at the application layer, before queries reach the database.
- ✗
Implement dynamic data masking to hide sensitive data from unauthorized users.
Why it's wrong here
Dynamic data masking hides column values in query results but does not stop injected SQL from executing or altering data. It is tempting because it is a genuine security feature, and it would be correct when the requirement is limiting exposure of sensitive data to non-privileged users rather than preventing injection.
- ✓
Use a web application firewall (WAF) in front of the application to filter malicious inputs.
Why this is correct
A web application firewall inspects inbound HTTP requests and blocks common injection payloads before they reach the application, adding a perimeter filtering layer. It reduces the attack surface but must be combined with parameterised queries for defence in depth.
- ✗
Enable Transparent Data Encryption (TDE) to encrypt the database at rest.
Why it's wrong here
TDE encrypts data and backups at rest; it does not inspect or block malicious SQL statements, so injection still executes. It is tempting because it is a core database security control, and it would be correct when the requirement is compliance-driven encryption of stored data rather than input validation.
Go deeper
Related to this question
Learn chapter
Optimizing Database Query and Index Performance
Key term
Transparent Data Encryption
Transparent Data Encryption is a security feature that automatically encrypts data written to a database and decrypts it when read, without requiring any changes to the application.
Key term
Azure SQL Performance Tuning
Azure SQL Performance Tuning is the process of optimizing the speed and efficiency of queries and database operations in Microsoft Azure SQL Database or SQL Managed Instance to reduce latency and improve throughput.
About these practice questions
This DP-300 question is part of Courseiva's 574-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DP-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-300 exam.