QuestionQ14

Implement a secure environment

You have an Azure subscription containing a SQL Server on Azure Virtual Machines instance named SQLVM1 and a Windows Server virtual machine named Server1. SQLVM1 and Server1 are joined to an Active Directory Domain Services (AD DS) domain. Server1 hosts a file share named Share1.

Ensure that a SQL Server Agent job step on SQLVM1 can access the files in Share1 while following the principle of least privilege.

Which three actions should you perform, in order?

Drag & Drop
Explanation

A SQL Server Agent proxy lets a job step run under a least-privilege Windows account. First create a credential for that account, then create a proxy that uses the credential, and finally assign the proxy to the job step. The Windows account must also have the necessary permissions on Share1.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!