Courseiva

DP-300 Implement a secure environment Practice Question

Your Azure SQL Database is accessed by multiple applications. You need to ensure that all connections use Transport Layer Security (TLS) 1.2 or higher. Which TWO configurations should you verify or enable?

⚠ Common exam trap

Watch out — candidates often confuse network-level controls (like NSGs) with TLS-level enforcement, or mistakenly apply on-premises SQL Server settings (like 'ForceEncryption') to Azure SQL Database, which has different configuration mechanisms and defaults.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure client applications to use TLS 1.2 in their connection strings.

Option A is correct because client-side enforcement is required: applications must be configured to negotiate TLS 1.2 or higher (for example, via the connection string or the underlying driver/provider settings), otherwise a client may still attempt to negotiate an older protocol version. Option D is correct because Azure SQL Database (and Azure SQL Managed Instance) exposes a server-level 'minimalTlsVersion' property that, when set to '1.2', rejects connections that attempt to negotiate TLS versions lower than 1.2. Together, A and D ensure both the client and the server enforce TLS 1.2 or higher. Option B is not appropriate because a network security group rule cannot inspect or enforce TLS protocol versions; NSGs filter by IP, port, and protocol (TCP/UDP), not by TLS version. Option C is not relevant because 'DenyPublicNetworkAccess' only controls whether public endpoints are reachable, not the TLS version used. Option E is not applicable because 'ForceEncryption' is a SQL Server on-premises/VM configuration option (set via sp_configure or the protocol properties), not an Azure SQL Database server property.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Configure client applications to use TLS 1.2 in their connection strings.

    Why this is correct

    Client-side protocol negotiation determines the TLS version actually used, so applications must request TLS 1.2 or higher in their connection strings. Server enforcement alone cannot upgrade a client that offers only TLS 1.0 or 1.1.

  • ✗

    Create a network security group rule to block non-TLS traffic.

    Why it's wrong here

    A network security group filters traffic by IP address, port and protocol, and cannot inspect the TLS handshake to determine the negotiated version. It is tempting because NSGs do restrict connectivity, and would be correct for blocking specific source addresses or ports rather than enforcing TLS 1.2.

  • ✗

    Set 'DenyPublicNetworkAccess' to 'Yes' on the server.

    Why it's wrong here

    DenyPublicNetworkAccess controls whether connections arrive over the public endpoint or private endpoints only; it does not restrict the TLS protocol version negotiated. It is tempting as a hardening measure, and would be correct when the requirement is to eliminate public internet exposure entirely.

  • ✓

    Set the server's 'minimalTlsVersion' property to '1.2'.

    Why this is correct

    Setting the server's minimalTlsVersion to 1.2 enforces the minimum TLS version at the logical server level, rejecting any connection negotiated below TLS 1.2. This directly satisfies the stem's requirement that all applications connecting to the Azure SQL Database use TLS 1.2 or higher, regardless of client configuration.

  • ✗

    Enable 'ForceEncryption' on the SQL Server instance.

    Why it's wrong here

    ForceEncryption applies to Azure SQL Managed Instance and SQL Server on Azure VMs, not Azure SQL Database, where TLS enforcement is handled by the server's minimum TLS version setting. It is tempting because it does enforce encrypted connections, but only on platforms where the instance-level property exists.

Go deeper

Related to this question

About these practice questions

Courseiva writes every DP-300 question from scratch — 574 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DP-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-300 exam.