Courseiva

AZ-500 Secure compute, storage, and databases Practice Question

A company has an Azure SQL Database that contains sensitive financial data. They want to audit all successful and failed login attempts for the database. What should they configure?

⚠ Common exam trap

Watch out — candidates often confuse Microsoft Entra ID sign-in logs (which track Microsoft Entra ID authentication) with SQL Database login auditing, failing to realize that SQL Database auditing is the only feature that captures all authentication attempts at the database engine level, including SQL authentication and contained database users.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Azure SQL Database auditing

Azure SQL Database auditing is the correct configuration because it captures both successful and failed login attempts (authentication events) at the database level. Auditing writes these events to an audit log destination (such as Azure Storage, Log Analytics, or Event Hubs), enabling detailed forensic analysis of access patterns. This directly meets the requirement to audit all login attempts for the sensitive financial database.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Azure SQL Database auditing

    Why this is correct

    Azure SQL Database auditing records both failed and successful login attempts to the SQL database, along with all database events such as INSERT, UPDATE, and DELETE operations. It writes the audit logs to an Azure Storage account, Log Analytics workspace, or Event Hub, giving a complete, queryable audit trail of who accessed the database and what actions they performed. This makes it the correct service for detecting and investigating sensitive-data access or brute-force login attempts.

  • ✗

    SQL Vulnerability Assessment

    Why it's wrong here

    SQL Vulnerability Assessment is a scanning engine that evaluates your Azure SQL Database for security misconfigurations, such as excessive permissions or missing data-masking policies, and classifies findings by risk severity. It does not capture runtime login events or any other real-time audit trail; it is a static, periodic review of configuration and schema rather than a record of actual access. Therefore, it cannot satisfy the requirement to audit database logins.

  • ✗

    Microsoft Defender for Cloud alerts

    Why it's wrong here

    Microsoft Defender for Cloud alerts provide adaptive threat-detection signals, such as unusual access patterns or SQL injection attempts, but these alerts are generated from anomaly detection heuristics rather than a complete event log. They intentionally trigger only on suspicious activity, so they do not include every successful and failed login, and they lack the granular, comprehensive audit details needed for full forensic reconstruction. As a result, they complement auditing but do not replace it.

  • ✗

    Microsoft Entra ID sign-in logs

    Why it's wrong here

    Microsoft Entra ID sign-in logs record authentication events against the Microsoft Entra ID identity provider, such as user logins to Office 365 or Azure Portal, and they also log service principal authentication to Azure resources. However, Azure SQL Database often uses SQL authentication (database-contained users) or Microsoft Entra ID authentication to the SQL database itself, and the sign-in logs show the network-level authentication to Azure, not the specific database login or subsequent database operations. So they provide only an upstream layer of identity activity, not a full audit of SQL database logins.

About these practice questions

This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.