DP-300 Implement a secure environment Practice Question
Your Azure SQL Database is accessed by multiple applications. You need to ensure that all connections use Transport Layer Security (TLS) 1.2 or higher. Which TWO configurations should you verify or enable?
⚠ Common exam trap
Watch out — candidates often confuse network-level controls (like NSGs) with TLS-level enforcement, or mistakenly apply on-premises SQL Server settings (like 'ForceEncryption') to Azure SQL Database, which has different configuration mechanisms and defaults.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure client applications to use TLS 1.2 in their connection strings.
Option A is correct because client-side enforcement is required: applications must be configured to negotiate TLS 1.2 or higher (for example, via the connection string or the underlying driver/provider settings), otherwise a client may still attempt to negotiate an older protocol version. Option D is correct because Azure SQL Database (and Azure SQL Managed Instance) exposes a server-level 'minimalTlsVersion' property that, when set to '1.2', rejects connections that attempt to negotiate TLS versions lower than 1.2. Together, A and D ensure both the client and the server enforce TLS 1.2 or higher. Option B is not appropriate because a network security group rule cannot inspect or enforce TLS protocol versions; NSGs filter by IP, port, and protocol (TCP/UDP), not by TLS version. Option C is not relevant because 'DenyPublicNetworkAccess' only controls whether public endpoints are reachable, not the TLS version used. Option E is not applicable because 'ForceEncryption' is a SQL Server on-premises/VM configuration option (set via sp_configure or the protocol properties), not an Azure SQL Database server property.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Configure client applications to use TLS 1.2 in their connection strings.
Why this is correct
Client-side protocol negotiation determines the TLS version actually used, so applications must request TLS 1.2 or higher in their connection strings. Server enforcement alone cannot upgrade a client that offers only TLS 1.0 or 1.1.
- ✗
Create a network security group rule to block non-TLS traffic.
Why it's wrong here
A network security group filters traffic by IP address, port and protocol, and cannot inspect the TLS handshake to determine the negotiated version. It is tempting because NSGs do restrict connectivity, and would be correct for blocking specific source addresses or ports rather than enforcing TLS 1.2.
- ✗
Set 'DenyPublicNetworkAccess' to 'Yes' on the server.
Why it's wrong here
DenyPublicNetworkAccess controls whether connections arrive over the public endpoint or private endpoints only; it does not restrict the TLS protocol version negotiated. It is tempting as a hardening measure, and would be correct when the requirement is to eliminate public internet exposure entirely.
- ✓
Set the server's 'minimalTlsVersion' property to '1.2'.
Why this is correct
Setting the server's minimalTlsVersion to 1.2 enforces the minimum TLS version at the logical server level, rejecting any connection negotiated below TLS 1.2. This directly satisfies the stem's requirement that all applications connecting to the Azure SQL Database use TLS 1.2 or higher, regardless of client configuration.
- ✗
Enable 'ForceEncryption' on the SQL Server instance.
Why it's wrong here
ForceEncryption applies to Azure SQL Managed Instance and SQL Server on Azure VMs, not Azure SQL Database, where TLS enforcement is handled by the server's minimum TLS version setting. It is tempting because it does enforce encrypted connections, but only on platforms where the instance-level property exists.
Go deeper
Related to this question
Learn chapter
Migrating On-Premises Databases to Azure
Key term
Azure SQL Performance Tuning
Azure SQL Performance Tuning is the process of optimizing the speed and efficiency of queries and database operations in Microsoft Azure SQL Database or SQL Managed Instance to reduce latency and improve throughput.
Key term
Azure SQL Managed Instance
Azure SQL Managed Instance is a fully managed cloud database service that gives you nearly all the features of Microsoft SQL Server on your own server, without you having to manage the hardware or operating system.
About these practice questions
Courseiva writes every DP-300 question from scratch — 574 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DP-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-300 exam.