DP-300 Practice Question: Monitor, configure, and optimize database resources
Your Azure SQL Database is configured with Active Geo-Replication to a secondary region for disaster recovery. During a routine failover drill, you notice that after failover, the application cannot connect to the new primary because the login credentials fail. The logins are contained in the master database. What is the most likely cause?
⚠ Common exam trap
A common mix-up: candidates assume all server-level configurations, including logins, are automatically replicated with geo-replication, but in reality, only user databases are replicated, not the master database.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The SQL logins in the master database are not replicated to the secondary server.
When Active Geo-Replication is configured for Azure SQL Database, the secondary server is a separate logical server in a different region. The master database, which contains server-level logins, is not replicated as part of geo-replication; only the user databases are replicated. Therefore, after a failover, the new primary server does not have the server-level logins from the original primary, causing authentication failures for applications using those logins.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The DNS name of the secondary server changed after failover.
Why it's wrong here
The secondary server's DNS name is unchanged by failover; only the role changes, and the application connects via the listener or server name as before. It is tempting because DNS resolution issues do break connectivity, and would be the cause if clients were failing to resolve the endpoint at all.
- ✓
The SQL logins in the master database are not replicated to the secondary server.
Why this is correct
Active Geo-Replication replicates user databases only; the logical server's master database, which holds server-level SQL logins, is not synchronised to the secondary server. After failover, those logins are absent, so authentication fails. Contained database users, stored inside the user database, would replicate and continue working.
- ✗
The firewall rules on the secondary server do not allow connections from the application IP.
Why it's wrong here
Firewall rules govern network reachability, not authentication; the error is a credential failure, so connectivity is already established. It is tempting because firewall misconfiguration is a common cause of failed connections after failover, and would be correct if the symptom were a timeout rather than a login rejection.
- ✗
The application uses contained database users, which are not replicated.
Why it's wrong here
Contained database users are stored in each database and do replicate to the secondary, so they would still authenticate. It is tempting because contained users are the recommended pattern for geo-replication, and would be correct if the logins were instead server-level logins in master, which do not replicate.
Go deeper
Related to this question
Learn chapter
Migrating On-Premises Databases to Azure
Key term
Azure SQL Performance Tuning
Azure SQL Performance Tuning is the process of optimizing the speed and efficiency of queries and database operations in Microsoft Azure SQL Database or SQL Managed Instance to reduce latency and improve throughput.
About these practice questions
This DP-300 question is part of Courseiva's 574-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DP-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-300 exam.