{"id":11845,"date":"2026-09-14T12:34:06","date_gmt":"2026-09-14T12:34:06","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=11845"},"modified":"2026-09-14T12:34:06","modified_gmt":"2026-09-14T12:34:06","slug":"microsoft-dp-800-practice-test-questions-and-exam-dumps-part-16-q301-q320","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/microsoft-dp-800-practice-test-questions-and-exam-dumps-part-16-q301-q320\/","title":{"rendered":"Microsoft DP-800 Practice Test Questions and Exam Dumps Part 16: Q301\u2013Q320"},"content":{"rendered":"<h2><b>View Full\u00a0<a href=\"https:\/\/www.examlabs.com\/dp-800-exam-dumps\">Microsoft DP-800 Exam Dumps<\/a>\u00a0and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 301<\/b><\/h3>\n<p><b>Which Azure SQL Database feature provides automatic failover capabilities between databases in different Azure regions?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure SQL Auditing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Auto-failover groups<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Query Store<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Elastic pools<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Auto-failover groups are designed to manage disaster recovery between Azure SQL databases in different regions. They provide a listener endpoint that applications can use to connect to the current primary database. During a regional failure or planned failover, databases can be switched to the secondary region. This reduces the need to change application connection strings manually. Administrators should configure failover groups according to recovery objectives and test failover procedures regularly.<\/span><\/p>\n<h3><b>Question 302<\/b><\/h3>\n<p><b>Which Azure SQL Database feature provides a secondary database that can be used for read workloads and disaster recovery?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Active geo-replication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Dynamic Data Masking<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Database auditing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Data compression<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Active geo-replication creates one or more readable secondary databases in different Azure regions. Changes from the primary database are replicated to the secondary database asynchronously. The secondary can support disaster recovery and, depending on application design, read-only workloads. Administrators can initiate a failover when required. Because replication is asynchronous, there can be some replication lag, so administrators should consider the possible amount of data loss when defining recovery objectives.<\/span><\/p>\n<h3><b>Question 303<\/b><\/h3>\n<p><b>Which Azure SQL Database availability option helps protect a database from a failure affecting an individual availability zone?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Zone redundancy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Query Store<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Elastic pool<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">BACPAC<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Zone redundancy distributes supported database resources across availability zones within an Azure region. This helps protect the database from certain failures affecting a single availability zone. Zone redundancy is different from geo-replication because it focuses on resilience within a region rather than maintaining a database copy in another region. Administrators should select availability options according to workload requirements, service-tier support, regional availability, recovery objectives, and cost considerations.<\/span><\/p>\n<h3><b>Question 304<\/b><\/h3>\n<p><b>Which recovery objective defines the maximum acceptable amount of data that can be lost after a failure?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RTO<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RPO<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SLA<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">MTTR<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Recovery Point Objective (RPO) defines the maximum amount of data loss that an organization is willing to accept after a failure. For example, an RPO of 15 minutes means the organization aims to recover with no more than approximately 15 minutes of data loss. Backup frequency, replication technology, and transaction-log protection can influence RPO. Administrators should establish RPO requirements with business stakeholders before designing backup and disaster recovery solutions.<\/span><\/p>\n<h3><b>Question 305<\/b><\/h3>\n<p><b>Which recovery objective defines the maximum acceptable time required to restore a service after a failure?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RPO<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">RTO<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SLA<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Recovery point<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Recovery Time Objective (RTO) defines how quickly a service or database should be restored after an outage. For example, an organization with an RTO of one hour expects the database service to be recovered within that target. Different recovery solutions provide different recovery times, so administrators must select technologies based on business requirements. Testing restores and failovers is also important because a documented recovery procedure does not guarantee that the target RTO can actually be achieved.<\/span><\/p>\n<h3><b>Question 306<\/b><\/h3>\n<p><b>Which Azure SQL Database capability can restore a database to a selected point within the available backup retention period?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Point-in-time restore<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Query Store<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Database auditing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Index rebuild<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Point-in-time restore allows administrators to create a restored database from automated backups at a selected time within the supported retention period. This is useful after accidental data deletion, incorrect updates, or application problems. The restored database can represent the state of the original database at the selected recovery point. Administrators should verify retention settings and regularly test restoration procedures to ensure that the required recovery points are actually available when needed.<\/span><\/p>\n<h3><b>Question 307<\/b><\/h3>\n<p><b>Which Azure SQL Database capability is designed to preserve backups for compliance or long-term retention requirements?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Long-term retention<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Query Store<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Automatic tuning<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Private Endpoint<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Long-term retention allows Azure SQL Database backups to be preserved for extended periods. Organizations can use this capability when regulations, auditing requirements, or internal policies require backups to remain available for months or years. LTR is different from normal short-term backup retention and should be planned according to business requirements. Administrators should also consider storage costs, retention policies, data residency requirements, and the process for restoring an archived backup.<\/span><\/p>\n<h3><b>Question 308<\/b><\/h3>\n<p><b>Which Azure SQL Database option provides private network connectivity without exposing the database through its public endpoint?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Private Endpoint<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public firewall rule<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Query Store<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Database snapshot<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Private Endpoint provides a private IP address for accessing supported Azure services from an Azure virtual network. For Azure SQL Database, this allows applications to connect through private network connectivity instead of using the public database endpoint. Administrators should also configure appropriate DNS resolution and network access controls. Private endpoints are useful when organizations want to reduce public exposure and enforce network isolation for applications and database services.<\/span><\/p>\n<h3><b>Question 309<\/b><\/h3>\n<p><b>Which Azure networking technology provides private connectivity to Azure services by using private endpoints?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Private Link<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Advisor<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Monitor<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Cost Management<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Private Link provides private connectivity to supported Azure services through private endpoints. Traffic can remain within Azure&#8217;s private networking infrastructure instead of traversing the public internet. For Azure SQL Database, Private Link can be used with a private endpoint to provide private access from an Azure virtual network. Administrators should configure DNS and network security correctly so applications resolve the database hostname to the appropriate private IP address.<\/span><\/p>\n<h3><b>Question 310<\/b><\/h3>\n<p><b>Which Azure SQL Database setting can prevent connections through the public endpoint?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public network access disabled<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Query Store enabled<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Automatic tuning enabled<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Long-term retention enabled<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Disabling public network access prevents access to the database through its public endpoint. Applications can instead use supported private connectivity, such as a private endpoint, when private access is required. This configuration can significantly reduce the public attack surface. Administrators should verify that required applications and management processes can reach the database through the private network before disabling public access, because an incorrect network configuration can unintentionally block legitimate connections.<\/span><\/p>\n<h3><b>Question 311<\/b><\/h3>\n<p><b>Which Azure SQL Database authentication method uses a username and password stored as SQL database credentials?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Microsoft Entra authentication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SQL authentication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Managed identity only<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Certificate authentication<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">SQL authentication uses a SQL login name and password to authenticate users or applications. It is a traditional authentication method supported by Azure SQL services. Administrators must protect SQL credentials carefully and follow strong password and security practices. Where possible, Microsoft Entra authentication or managed identities can reduce the need to manage passwords. Regardless of the authentication method, database permissions should follow the principle of least privilege.<\/span><\/p>\n<h3><b>Question 312<\/b><\/h3>\n<p><b>Which authentication approach is generally preferred when an Azure application needs to access Azure SQL without storing a password?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Managed identity<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SQL authentication with a hard-coded password<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Anonymous authentication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Guest account<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A managed identity allows an Azure resource to authenticate to supported services without storing a password or client secret in application code. Azure manages the identity credentials, reducing credential-management risks. Administrators can grant the managed identity only the database permissions it requires. This approach is especially useful for Azure applications accessing Azure SQL Database, Key Vault, Storage, and other Azure services. Proper authorization is still required after authentication succeeds.<\/span><\/p>\n<h3><b>Question 313<\/b><\/h3>\n<p><b>Which Azure SQL Database component can contain multiple databases under the same logical management boundary?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Logical server<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Database snapshot<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Table<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Schema<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An Azure SQL logical server can contain multiple Azure SQL databases and provides a management boundary for those databases. It also provides the server endpoint used for connections and can hold settings such as firewall configuration. A logical server should not be confused with a traditional SQL Server instance because Azure SQL Database is a platform service rather than a server that administrators manage at the operating-system level. The logical server is primarily an Azure management and connectivity concept.<\/span><\/p>\n<h3><b>Question 314<\/b><\/h3>\n<p><b>Which Azure SQL service generally requires integration with an Azure virtual network?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure SQL Managed Instance<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure SQL Database<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Storage<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Table Storage<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure SQL Managed Instance is deployed within an Azure virtual network and requires appropriate subnet networking configuration. This design supports many instance-level SQL Server capabilities and provides network integration suitable for enterprise workloads. Administrators must consider subnet configuration, routing, DNS, and network security when deploying Managed Instance. Azure SQL Database uses a different architecture and does not require administrators to deploy the database itself into a customer-managed virtual network.<\/span><\/p>\n<h3><b>Question 315<\/b><\/h3>\n<p><b>Which Azure SQL service provides the closest compatibility with traditional SQL Server instance-level workloads while remaining a managed service?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure SQL Managed Instance<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure SQL Database serverless<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Storage<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Cosmos DB<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure SQL Managed Instance provides a managed SQL Server environment with broad compatibility for traditional SQL Server workloads. It supports many instance-level features and capabilities that make migration easier for applications that depend on features beyond a single Azure SQL Database. Microsoft manages the infrastructure, patching, and platform operations. Administrators still manage databases, security, configuration, and workload performance. Managed Instance is often selected when minimizing application changes is an important migration goal.<\/span><\/p>\n<h3><b>Question 316<\/b><\/h3>\n<p><b>Which Azure option gives an administrator the greatest control over the Windows operating system running SQL Server?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure SQL Database<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure SQL Managed Instance<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SQL Server on Azure Virtual Machines<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Synapse Analytics<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">SQL Server on Azure Virtual Machines provides operating-system-level control because the SQL Server instance runs on a customer-managed Azure virtual machine. Administrators can manage the operating system, SQL Server installation, configuration, file locations, and many other settings. This flexibility also creates additional management responsibilities, including operating system patching and SQL Server maintenance. Organizations often choose this option when applications require specific SQL Server or operating-system configurations unavailable in fully managed services.<\/span><\/p>\n<h3><b>Question 317<\/b><\/h3>\n<p><b>Which Azure SQL service is best suited when an organization wants Microsoft to manage the operating system and database platform infrastructure?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SQL Server on Azure VM<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure SQL Database<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Self-hosted SQL Server<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SQL Server on a physical server<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure SQL Database is a platform-as-a-service offering in which Microsoft manages the underlying infrastructure and many administrative tasks. Administrators do not need to maintain the operating system or install SQL Server manually. Instead, they focus on database configuration, security, performance, connectivity, and application requirements. This reduces operational overhead compared with SQL Server running on a virtual machine. Azure SQL Database is appropriate when the workload can operate within the capabilities of the managed database platform.<\/span><\/p>\n<h3><b>Question 318<\/b><\/h3>\n<p><b>Which Azure service can provide centralized storage for SQL Server encryption keys and certificates?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Key Vault<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Monitor<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure Advisor<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Azure DNS<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Azure Key Vault provides secure storage and management for cryptographic keys, secrets, and certificates. SQL Server and Azure SQL-related solutions can integrate with Key Vault for supported encryption scenarios. Centralizing key management can improve security because sensitive cryptographic material does not need to be stored directly in application code or ordinary configuration files. Administrators should use appropriate identity permissions and access policies to ensure that only authorized services and users can access keys.<\/span><\/p>\n<h3><b>Question 319<\/b><\/h3>\n<p><b>Which security principle requires database users and applications to receive only the permissions they actually need?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Least privilege<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Maximum privilege<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Shared access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Anonymous access<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The principle of least privilege means users and applications should receive only the permissions necessary to perform their required tasks. This reduces the potential impact if an account is compromised or an application behaves unexpectedly. For example, an application that only needs to read data should not automatically receive permissions to modify or delete tables. Administrators can implement least privilege using database roles, specific GRANT permissions, Microsoft Entra identities, and carefully designed application accounts.<\/span><\/p>\n<h3><b>Question 320<\/b><\/h3>\n<p><b>Which T-SQL statement grants a user or role permission to perform a specific database operation?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DENY<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">REVOKE<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">GRANT<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DROP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The <\/span><span style=\"font-weight: 400;\">GRANT<\/span><span style=\"font-weight: 400;\"> statement gives a user, role, or other principal permission to perform a specific database operation. For example, an administrator can grant SELECT permission on a table or EXECUTE permission on a stored procedure. <\/span><span style=\"font-weight: 400;\">DENY<\/span><span style=\"font-weight: 400;\"> explicitly prevents a permission, while <\/span><span style=\"font-weight: 400;\">REVOKE<\/span><span style=\"font-weight: 400;\"> removes a previously granted or denied permission in the applicable permission hierarchy. Administrators should use GRANT carefully and follow least-privilege principles when designing database security.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full\u00a0Microsoft DP-800 Exam Dumps\u00a0and Practice Test Dumps. &nbsp; Question 301 Which Azure SQL Database feature provides automatic failover capabilities between databases in different Azure regions? Azure SQL Auditing Auto-failover groups Query Store Elastic pools Correct Answer: 2 Explanation Auto-failover groups are designed to manage disaster recovery between Azure SQL databases in different regions. They [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/11845"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=11845"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/11845\/revisions"}],"predecessor-version":[{"id":11846,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/11845\/revisions\/11846"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=11845"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=11845"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=11845"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}