Courseiva

DP-300 Azure SQL Database firewall Practice Question

Your organization uses Azure SQL Database and wants to restrict access to only specific on-premises IP addresses. The database has a public endpoint. Which security feature should you configure?

⚠ Common exam trap

Candidates might consider enabling 'Allow Azure services' or using virtual network endpoints, but those are for Azure service access or private network integration, not for restricting on-premises IPs.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Set firewall rules to allow specific on-premises IP ranges.

To restrict access to specific on-premises IP addresses, you should configure firewall rules to allow those IP ranges. Setting a firewall rule ensures that only traffic from allowed IP addresses can reach the database. Option C directly addresses this requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable 'Allow Azure services and resources to access this server' in the firewall settings.

    Why it's wrong here

    Server-level firewall rules must specify the on-premises IP ranges; this toggle instead permits all Azure-hosted services, including other tenants' resources, to connect. It is tempting because it is used when Azure services such as Data Factory or Logic Apps need to reach the database, but it does not restrict access to named on-premises addresses.

  • ✗

    Enable Always Encrypted with secure enclaves.

    Why it's wrong here

    Always Encrypted with secure enclaves protects column data during computation; it performs no network filtering, so any on-premises address can still reach the public endpoint. It is tempting because it is a database security feature, and would be correct when protecting sensitive columns from DBAs rather than restricting client IP ranges.

  • ✓

    Set firewall rules to allow specific on-premises IP ranges.

    Why this is correct

    Server-level and database-level firewall rules filter inbound connections by source IP address at the Azure SQL gateway, permitting only the listed on-premises ranges while blocking all other public traffic. This directly satisfies the requirement to restrict the public endpoint to specific on-premises addresses.

  • ✗

    Create a virtual network service endpoint for SQL.

    Why it's wrong here

    A virtual network service endpoint restricts traffic to subnets inside an Azure VNet, so on-premises addresses cannot be allow-listed through it. It is tempting because it hardens SQL traffic, and would be correct when only Azure virtual machines in specific subnets should reach the server.

  • ✗

    Configure a private endpoint for the database.

    Why it's wrong here

    A private endpoint assigns a private IP inside a VNet, removing the public endpoint entirely, so on-premises clients cannot connect over their existing public addresses. It is tempting because it eliminates public exposure, and would be correct when all access should traverse private connectivity such as VPN or ExpressRoute.

About these practice questions

One of 574 original DP-300 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DP-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-300 exam.