Courseiva

DP-300 Implement a secure environment Practice Question

Your organization uses Azure SQL Managed Instance and needs to implement a defense-in-depth strategy. Which THREE security controls should you implement? (Choose three.)

⚠ Common exam trap

Many exam-takers confuse performance tuning features (like columnstore indexes) or routine permission management (like application roles) with distinct security controls, failing to recognize that defense-in-depth requires separate, layered protections across network, monitoring, and auditing domains.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable advanced threat protection using Microsoft Defender for Cloud.

Option A is correct because enabling advanced threat protection via Microsoft Defender for Cloud provides detection and alerting for anomalous activities and potential vulnerabilities on Azure SQL Managed Instance, which is a core detective control in a defense-in-depth strategy. Option B is correct because server-level auditing captures database events and writes them to an audit log, providing the monitoring and traceability required for a layered security approach. Option D is correct because configuring network security groups (NSGs) on the subnet restricts inbound traffic to the managed instance, enforcing network-level segmentation and reducing the attack surface, which is a fundamental preventive control. Option C is not a security control; columnstore indexes are a performance optimization for analytical workloads and do not contribute to defense-in-depth. Option E is not the best fit because application roles manage permissions within a database but do not address the broader layered security controls expected in a defense-in-depth strategy for Azure SQL Managed Instance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Enable advanced threat protection using Microsoft Defender for Cloud.

    Why this is correct

    Microsoft Defender for Cloud's advanced threat protection detects anomalous access patterns and brute-force attempts against Azure SQL Managed Instance, raising alerts for suspicious logins and potential SQL injection. This satisfies the defence-in-depth requirement by adding a detective control layer beyond authentication and network isolation, enabling rapid response to compromised credentials or exploitation attempts.

  • ✓

    Implement server-level auditing to capture database events.

    Why this is correct

    Server-level auditing records database events to Azure Storage, Log Analytics or Event Hubs, providing the detective control that defence-in-depth requires alongside network and identity layers. It captures login successes and failures across every database on the managed instance, satisfying the monitoring constraint in the stem.

  • ✗

    Create columnstore indexes on large tables to improve query performance.

    Why it's wrong here

    Columnstore indexes are a query-performance feature for analytical workloads, not a security control, so they add nothing to a defence-in-depth strategy. They are tempting because they genuinely accelerate large-table scans in data-warehousing scenarios, but the stem asks for security controls such as auditing, TDE, and Microsoft Entra authentication.

  • ✓

    Configure network security groups (NSGs) on the subnet to restrict inbound traffic to the managed instance.

    Why this is correct

    NSGs filter traffic at the subnet boundary, so inbound connections to the managed instance's port 1433 can be restricted to approved sources. This supplies the network-layer control that defence-in-depth demands, since the managed instance sits inside a delegated subnet where NSG rules govern reachability.

  • ✗

    Create application roles in each database to manage permissions.

    Why it's wrong here

    Application roles grant permissions to an application rather than to individual database users, so they do not enforce the authentication and authorisation boundaries defence-in-depth requires. They are tempting because they simplify permission management for apps connecting to a database, which is useful when many users share one application identity, but that is not a security control here.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

This DP-300 question is part of Courseiva's 574-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DP-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-300 exam.