Microsoft DP-300 Exam Questions
Administering Microsoft Azure SQL Solutions (Page 24 )

Updated On: 17-Feb-2026
View Related Case Study

DRAG DROP (Drag and Drop is not supported)

You need to recommend an authentication solution for App1 access to DB1 and DB2 after their migration to Instance1. The solution must meet the availability requirements.

Which actions should you perform in sequence? To answer, drag the appropriate actions to the correct order. Each action may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.

Note: Each correct selection is worth one point.

Select and Place:

  1. See Explanation section for answer.

Answer(s): A

Explanation:






Step 2: Implement Microsoft Entra Cloud Sync
How to set up Windows Authentication for Azure SQL Managed Instance using Microsoft Entra ID and Kerberos

One-time infrastructure setup
The first step in infrastructure setup is to synchronize AD with Microsoft Entra ID, if this hasn't already been completed.

Synchronize AD with Microsoft Entra ID
Customers should first implement Microsoft Entra Connect to integrate on-premises directories with Microsoft Entra ID.

Microsoft Entra Connect is an on-premises Microsoft application that's designed to meet and accomplish your hybrid identity goals. If you're evaluating how to best meet your goals, you should also consider the cloud- managed solution Microsoft Entra Cloud Sync.

Note: There are two phases to set up Windows Authentication for Azure SQL Managed Instance using Microsoft Entra ID and Kerberos.

* One-time infrastructure setup.
- Synchronize Active Directory (AD) and Microsoft Entra ID, if this hasn't already been done.
- Etc

* Configuration of Azure SQL Managed Instance.
Create a system assigned service principal for each managed instance.

Step 3: Enable a system-assigned service principal

Scenario:
App1 runs on Microsoft Entra hybrid joined servers that run Windows Server 2022. App1 uses Kerberos authentication.

After the migration, App1 must maintain access to DB1 and DB2.

Planned Changes
Deploy an Azure SQL managed instance named Instance1 to Network1.
Migrate DB1 and DB2 to Instance1.

Incorrect:
* Grant admin consent to an app registration in Microsoft Entra When you grant tenant-wide admin consent to an application, you give the application access to the permissions requested on behalf of the whole organization. Granting admin consent on behalf of an organization is a sensitive operation, potentially allowing the application's publisher access to significant portions of your organization's data, or the permission to do highly privileged operations. Examples of such operations might be role management, full access to all mailboxes or all sites, and full user impersonation. Therefore, you need to carefully review the permissions that the application is requesting before you grant consent.


Reference:

https://learn.microsoft.com/en-us/azure/azure-sql/managed-instance/winauth-implementation-aad-kerberos https://learn.microsoft.com/en-us/azure/azure-sql/managed-instance/winauth-azuread-setup https://learn.microsoft.com/en-us/entra/identity/hybrid/connect/whatis-azure-ad-connect



View Related Case Study

You need to recommend a solution that will enable remote developers to access DB1 and DB2. The solution must support the planned changes and meet the security requirements.

What should you include in the recommendation?

  1. a public endpoint via a database-level firewall rule
  2. a Point-to-Site (P2S) VPN
  3. a public endpoint via a server-level firewall rule
  4. a private endpoint

Answer(s): D

Explanation:

Azure SQL Managed Instance is secured using network security rules and private endpoints.
Private endpoints
A private endpoint is an optional fixed IP address in another virtual network that conducts traffic to your SQL managed instance. One Azure SQL Managed Instance can have multiple private endpoints in multiple virtual networks. Private endpoints allow TDS traffic only to reach SQL Managed Instance on port 1433 and can't be used for integration scenarios, such as failover groups, Managed Instance link, and other similar technologies.
When connecting to a private endpoint, always use the domain name since connecting to Azure SQL Managed Instance via its IP address isn't supported yet.
Scenario:
Requirements. Planned Changes
Deploy an Azure SQL managed instance named Instance1 to Network1.
Migrate DB1 and DB2 to Instance1
Following the migration of DB1 and DB2, hand over database development to remote developers who use Microsoft Entra joined Windows 11 devices.
Requirements. Security Requirements
ADatum identifies the following security requirements for after the migration:
Ensure that only designated developers who use Microsoft Entra joined Windows 11 devices can access DB1
and DB2 remotely.


Reference:

https://learn.microsoft.com/en-us/azure/azure-sql/managed-instance/connectivity-architecture-overview



View Related Case Study

DRAG DROP (Drag and Drop is not supported)

You create all of the tables and views for ResearchDB1.

You need to implement security for ResearchDB1. The solution must meet the security and compliance requirements.

Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Select and Place:

  1. See Explanation section for answer.

Answer(s): A

Explanation:





Box 1: - Register ResearchApp1 to Microsoft Entra ID.

Box 2: Create an Azure Key Vault instance and configure an access policy. Need to configure the key vault with an access policy to enable ResearchApp1 retrieval of the keys.

Box 3: Run the Always Encrypt wizard.
Run the Always Encrypt wizard to encrypt the columns and store the encryption keys in the vault.


Reference:

https://docs.microsoft.com/en-us/azure/azure-sql/database/always-encrypted-azure-key-vault-configure? tabs=azure-powershell



View Related Case Study

DRAG DROP (Drag and Drop is not supported)

You need to configure user authentication for the SERVER1 databases. The solution must meet the security and compliance requirements.

Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.

Select and Place:

  1. See Explanation section for answer.

Answer(s): A

Explanation:






Scenario: Authenticate database users by using Active Directory credentials.

The configuration steps include the following procedures to configure and use Microsoft Entra authentication.

1. Create and populate Microsoft Entra ID.
2. Optional: Associate or change the active directory that is currently associated with your Azure Subscription.
3. Create a Microsoft Entra administrator. (Step 1)
4. Connect to the databases using a Microsoft Entra account (the Administrator account that was configured in the previous step). (Step 2)
5. Create contained database users in your database mapped to Microsoft Entra identities. (Step 3)


Reference:

https://docs.microsoft.com/en-us/azure/azure-sql/database/authentication-aad-configure?tabs=azure- powershell



View Related Case Study

HOTSPOT (Drag and Drop is not supported)

You are evaluating the role assignments.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.

Note: Each correct selection is worth one point.

Hot Area:

  1. See Explanation section for answer.

Answer(s): A

Explanation:





Box 1: No
DBAGroup1 is member of the Contributor role.
The Contributor role grants full access to manage all resources, but does not allow you to assign roles in Azure RBAC, manage assignments in Azure Blueprints, or share image galleries.

Box 2: No
Contributor - Grants full access to manage all resources, but does not allow you to assign roles in Azure RBAC SQL DB Contributor - Lets you manage SQL databases, but not access to them. Also, you can't manage their security-related policies or their parent SQL servers.

Box 3: Yes
DBAGroup2 is member of the SQL DB Contributor role.
The SQL DB Contributor role lets you manage SQL databases, but not access to them. Also, you can't manage their security-related policies or their parent SQL servers. As a member of this role you can create and manage SQL databases.


Reference:

https://docs.microsoft.com/en-us/azure/role-based-access-control/built-in-roles






Post your Comments and Discuss Microsoft DP-300 exam dumps with other Community members:

Join the DP-300 Discussion