Courseiva

DP-300 Reader role Practice Question

Your organization has Azure SQL Database with several databases. You need to implement a solution that allows a junior DBA to view the security logs for failed logins but not modify any security settings. What is the minimum role assignment needed on the logical server?

⚠ Common exam trap

Candidates may assume the generic Reader role is enough for any read-only task, but SQL security logs require the SQL Security Manager role, which is the minimum role that grants visibility into those logs.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Assign the SQL Security Manager role.

The SQL Security Manager role is the minimum built-in Azure RBAC role that grants read access to SQL security-related logs, including failed login audit logs, at the logical server scope. While it can also manage security policies, it is the least-privileged built-in role that satisfies the requirement to view the failed login security logs. The Reader role only provides read access to Azure resource metadata and does not expose SQL security logs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Assign the SQL Security Manager role.

    Why this is correct

    Incorrect because the SQL Security Manager role allows updating security policies, which is more than read-only access and violates the requirement to not modify security settings.

  • ✗

    Assign the Reader role.

    Why it's wrong here

    Correct because the Reader role provides read-only access to all resources, including security logs, with no modification permissions.

  • ✗

    Assign the Contributor role.

    Why it's wrong here

    Incorrect because the Contributor role allows creating and managing resources, which includes modifying security settings, thus granting excessive permissions.

  • ✗

    Assign the SQL DB Contributor role.

    Why it's wrong here

    Incorrect because the SQL DB Contributor role allows full management of databases, including security settings, which exceeds the required read-only access.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

This DP-300 question is part of Courseiva's 574-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DP-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-300 exam.