DP-300 Implement a secure environment Practice Question
Your Azure SQL Database is accessed by three separate applications. You must ensure that each application can connect only from its own set of IP addresses, that the addresses are managed centrally without editing each database, and that no application can reach the database over the public internet from any other address. What should you implement?
⚠ Common exam trap
Candidates often confuse which firewall scope applies where, leading to database-level rules when the requirement is centralized management across all databases on the server.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create server-level firewall rules, one per application, containing that application's IP ranges
Server-level firewall rules are evaluated for the logical server and apply to all its databases, so they centralize address management while letting you define a distinct rule per application. Database-level rules scatter the configuration, the Azure services toggle admits too much, and service endpoints constrain to virtual network subnets rather than per-application address ranges.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable the Allow Azure services and resources to access this server rule and rely on database permissions per application
Why it's wrong here
This rule admits a broad range of Azure-originated traffic rather than specific application addresses, so an application on a different Azure resource could connect. Database permissions control what a principal can do after connecting, not which addresses may connect. This fails the requirement that each application connect only from its own addresses.
- ✗
Create a database-level firewall rule in each database for the corresponding application's addresses
Why it's wrong here
Database-level rules are scoped to a single database, so managing three applications across multiple databases means editing rules repeatedly and risking drift. The requirement is centralized management, which this approach works against. It also does not inherently prevent other addresses from reaching databases that lack their own rules.
- ✗
Configure a virtual network service endpoint and a network security group that permits the three application subnets
Why it's wrong here
Service endpoints restrict access to specified subnets and are a valid pattern, but they limit connectivity to resources in those virtual networks and do not centrally express per-application address sets for arbitrary clients. The question requires managing distinct address ranges per application from one place, which server-level rules express more directly than subnet-based endpoint rules.
- ✓
Create server-level firewall rules, one per application, containing that application's IP ranges
Why this is correct
Server-level firewall rules apply to the logical server and therefore to every database it hosts, so the addresses are managed in one place rather than per database. Defining a separate rule per application restricts each to its own ranges. Because the firewall denies traffic that does not match a rule, other addresses cannot reach the database.
Visual reference
Go deeper
Related to this question
Learn chapter
Deploying and Configuring SQL Server on Azure Virtual Machines
Key term
Azure SQL Performance Tuning
Azure SQL Performance Tuning is the process of optimizing the speed and efficiency of queries and database operations in Microsoft Azure SQL Database or SQL Managed Instance to reduce latency and improve throughput.
About these practice questions
One of 574 original DP-300 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This DP-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-300 exam.