DP-700 Ingest and Transform Data Practice Question
You need to ingest data from an Azure SQL Database that is protected by a firewall and does not allow public network access. Which Fabric feature should you use to establish a secure connection without opening the firewall to all Azure services?
⚠ Common exam trap
Test-takers frequently confuse VNet Data Gateways or public endpoint IP whitelisting with Managed Private Endpoints, forgetting that secure intra-cloud connectivity behind strict firewalls requires private endpoints.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Managed Private Endpoint.
Managed Private Endpoints in Microsoft Fabric allow for secure, private connectivity to data sources that are behind firewalls or restricted to private networks. They ensure that data traffic remains within the Microsoft network backbone and provide a specific, secure path for ingestion activities like Dataflows and Pipelines.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
On-premises Data Gateway.
Why it's wrong here
The On-premises Data Gateway is primarily used for connecting to data sources located within a local corporate network (on-prem). For cloud-based resources like Azure SQL behind a firewall, Managed Private Endpoints are the preferred and more integrated solution within the Fabric architecture.
- ✓
Managed Private Endpoint.
Why this is correct
Managed Private Endpoints allow Fabric to connect to Azure services securely by creating a private link. This avoids exposing the source database to the public internet and allows the database administrator to grant access specifically to the Fabric workspace through a private IP address.
- ✗
Service Principal Authentication.
Why it's wrong here
Service Principal Authentication is an identity and access management method. While it is used to authenticate the connection, it does not solve the networking challenge of bypassing a firewall that blocks all traffic not originating from an authorized private network or IP address.
- ✗
OneLake Shortcut.
Why it's wrong here
Shortcuts are used to virtualize data from external storage accounts like ADLS Gen2. They do not provide a general-purpose networking solution for connecting to relational databases like Azure SQL that are restricted by network security rules or complex firewall configurations.
About these practice questions
This DP-700 question is part of Courseiva's 152-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This DP-700 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-700 exam.