Courseiva

DP-300 Implement a secure environment Practice Question

Your company plans to use Azure SQL Managed Instance for a mission-critical application. You need to ensure that all connections to the database are encrypted and that the server's identity is verified. Which configuration should you enforce?

⚠ Common exam trap

Candidates often confuse 'Trust Server Certificate' = ON as a convenience setting that simplifies connections, not realizing it disables certificate validation and undermines security for mission-critical workloads.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Set 'Force Encryption' = ON and 'Trust Server Certificate' = OFF

Setting 'Force Encryption' = ON ensures that all connections to Azure SQL Managed Instance use TLS encryption, while setting 'Trust Server Certificate' = OFF forces the client to validate the server's certificate against a trusted certificate authority (CA). This combination guarantees both data-in-transit encryption and server identity verification, meeting the requirement for a mission-critical application.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Set 'Force Encryption' = OFF and 'Trust Server Certificate' = OFF

    Why it's wrong here

    Force Encryption = OFF allows clients to connect without TLS, so connections are not guaranteed to be encrypted. It is tempting because Trust Server Certificate = OFF does enforce identity verification, appearing to satisfy half the requirement. Both settings must be ON and OFF respectively to meet the stem.

  • ✓

    Set 'Force Encryption' = ON and 'Trust Server Certificate' = OFF

    Why this is correct

    Forcing encryption guarantees the connection is TLS-protected, while disabling Trust Server Certificate compels the client to validate the server certificate chain against a trusted authority, verifying the instance's identity. This satisfies both the encryption and identity-verification requirements without bypassing certificate validation, unlike trusting self-signed certificates.

  • ✗

    Set 'Force Encryption' = ON and 'Trust Server Certificate' = ON

    Why it's wrong here

    Trust Server Certificate = ON makes the client skip certificate-chain and hostname validation, so the server's identity is never verified — encryption alone is insufficient. It is tempting because it avoids certificate errors during setup. Verification requires Trust Server Certificate = OFF with a trusted certificate chain.

  • ✗

    Set 'Force Encryption' = OFF and 'Trust Server Certificate' = ON

    Why it's wrong here

    Force Encryption = OFF permits unencrypted connections, and Trust Server Certificate = ON disables server identity validation, failing both requirements. It is tempting because it mirrors default client behaviour and avoids certificate errors. Encryption and verification require Force Encryption = ON with Trust Server Certificate = OFF.

About these practice questions

This DP-300 question is part of Courseiva's 574-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DP-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-300 exam.