DP-300 Reader role Practice Question
Your organization has Azure SQL Database with several databases. You need to implement a solution that allows a junior DBA to view the security logs for failed logins but not modify any security settings. What is the minimum role assignment needed on the logical server?
⚠ Common exam trap
Candidates may assume the generic Reader role is enough for any read-only task, but SQL security logs require the SQL Security Manager role, which is the minimum role that grants visibility into those logs.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Assign the SQL Security Manager role.
The SQL Security Manager role is the minimum built-in Azure RBAC role that grants read access to SQL security-related logs, including failed login audit logs, at the logical server scope. While it can also manage security policies, it is the least-privileged built-in role that satisfies the requirement to view the failed login security logs. The Reader role only provides read access to Azure resource metadata and does not expose SQL security logs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Assign the SQL Security Manager role.
Why this is correct
Incorrect because the SQL Security Manager role allows updating security policies, which is more than read-only access and violates the requirement to not modify security settings.
- ✗
Assign the Reader role.
Why it's wrong here
Correct because the Reader role provides read-only access to all resources, including security logs, with no modification permissions.
- ✗
Assign the Contributor role.
Why it's wrong here
Incorrect because the Contributor role allows creating and managing resources, which includes modifying security settings, thus granting excessive permissions.
- ✗
Assign the SQL DB Contributor role.
Why it's wrong here
Incorrect because the SQL DB Contributor role allows full management of databases, including security settings, which exceeds the required read-only access.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
Learn chapter
Managing Environment Configurations and Resource Governance
Key term
Azure SQL Performance Tuning
Azure SQL Performance Tuning is the process of optimizing the speed and efficiency of queries and database operations in Microsoft Azure SQL Database or SQL Managed Instance to reduce latency and improve throughput.
About these practice questions
This DP-300 question is part of Courseiva's 574-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DP-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-300 exam.