Courseiva

DP-300 Practice Question: Monitor, configure, and optimize database resources

Your Azure SQL Database is configured with Active Geo-Replication to a secondary region for disaster recovery. During a routine failover drill, you notice that after failover, the application cannot connect to the new primary because the login credentials fail. The logins are contained in the master database. What is the most likely cause?

⚠ Common exam trap

A common mix-up: candidates assume all server-level configurations, including logins, are automatically replicated with geo-replication, but in reality, only user databases are replicated, not the master database.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The SQL logins in the master database are not replicated to the secondary server.

When Active Geo-Replication is configured for Azure SQL Database, the secondary server is a separate logical server in a different region. The master database, which contains server-level logins, is not replicated as part of geo-replication; only the user databases are replicated. Therefore, after a failover, the new primary server does not have the server-level logins from the original primary, causing authentication failures for applications using those logins.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The DNS name of the secondary server changed after failover.

    Why it's wrong here

    The secondary server's DNS name is unchanged by failover; only the role changes, and the application connects via the listener or server name as before. It is tempting because DNS resolution issues do break connectivity, and would be the cause if clients were failing to resolve the endpoint at all.

  • ✓

    The SQL logins in the master database are not replicated to the secondary server.

    Why this is correct

    Active Geo-Replication replicates user databases only; the logical server's master database, which holds server-level SQL logins, is not synchronised to the secondary server. After failover, those logins are absent, so authentication fails. Contained database users, stored inside the user database, would replicate and continue working.

  • ✗

    The firewall rules on the secondary server do not allow connections from the application IP.

    Why it's wrong here

    Firewall rules govern network reachability, not authentication; the error is a credential failure, so connectivity is already established. It is tempting because firewall misconfiguration is a common cause of failed connections after failover, and would be correct if the symptom were a timeout rather than a login rejection.

  • ✗

    The application uses contained database users, which are not replicated.

    Why it's wrong here

    Contained database users are stored in each database and do replicate to the secondary, so they would still authenticate. It is tempting because contained users are the recommended pattern for geo-replication, and would be correct if the logins were instead server-level logins in master, which do not replicate.

About these practice questions

This DP-300 question is part of Courseiva's 574-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DP-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-300 exam.