Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel →hardMultiple ChoiceObjective-mapped
How to Enable Advanced Threat Protection for All Azure SQL Databases with Minimal Effort
Your organization is using Microsoft Defender for Cloud to protect Azure SQL databases. You need to enable Advanced Threat Protection (ATP) for all existing and future Azure SQL databases in a subscription. The solution must minimize administrative effort. What should you do?
Quick Answer
The answer is to enable the Azure SQL databases plan in Microsoft Defender for Cloud at the subscription level. This is correct because enabling Advanced Threat Protection for Azure SQL databases at scale is handled automatically by Defender for Cloud’s subscription-level plan, which applies protection to all existing and future databases without requiring per-resource configuration. On the AZ-500 exam, this scenario tests your understanding of centralized security policies versus manual, resource-by-resource enablement; a common trap is choosing Azure Policy, which can enforce the setting but adds unnecessary overhead when the direct subscription toggle achieves the same result with minimal effort. Remember that Defender for Cloud plans are designed for bulk activation—think of it as a master switch for your entire subscription. A useful memory tip: “One plan to rule them all” — subscription-level plans cover future resources automatically, so you never have to chase new databases.
⚠ Common exam trap
Candidates often confuse enabling a Defender for Cloud plan (which is a simple toggle at the subscription level) with creating an Azure Policy (which is a more complex, policy-as-code approach), leading them to choose Option C even though it requires more administrative effort than the direct plan enablement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable the Azure SQL databases plan in Microsoft Defender for Cloud at the subscription level.
Enabling the Azure SQL databases plan in Microsoft Defender for Cloud at the subscription level automatically enables Advanced Threat Protection (ATP) for all existing and future Azure SQL databases within that subscription. This approach requires minimal administrative effort because it applies the protection globally without needing to configure each database individually or create custom policies. Microsoft Defender for Cloud manages the ATP settings centrally, ensuring consistent security coverage across the entire subscription.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure Microsoft Sentinel to monitor Azure SQL databases.
Why it's wrong here
Incorrect. Sentinel is for SIEM, not enabling ATP.
- ✓
Enable the Azure SQL databases plan in Microsoft Defender for Cloud at the subscription level.
Why this is correct
Correct. Enabling the plan at the subscription level applies to all current and future resources.
- ✗
Create an Azure Policy to deploy Advanced Threat Protection on Azure SQL databases.
Why it's wrong here
Creating an Azure Policy to deploy Advanced Threat Protection (ATP) directly onto Azure SQL databases is incorrect because ATP is enabled at the subscription level through the Microsoft Defender for Cloud plan for Azure SQL databases. This plan automatically covers all existing and future databases with minimal administrative overhead. Azure Policy is tempting as it can enforce configurations and deploy resources, and would be the correct choice for auditing ATP compliance across SQL databases or ensuring specific database deployments adhere to security standards.
Go deeper
Related to this question
About these practice questions
One of 194 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on AZ-500
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Your organization uses Microsoft Defender for Cloud to protect Azure SQL databases. You need to enable Advanced Threat Protection (ATP) for Azure SQL. Where should you configure this?
easy- ✓ A.In the Azure SQL server blade under Security
- B.In the Microsoft Defender for Cloud subscription settings
- C.In the Azure resource group where the SQL server resides
- D.In the Azure SQL database blade under Security
Why A: Advanced Threat Protection (ATP) for Azure SQL is enabled at the Azure SQL server level, not at the individual database level, because ATP policies and threat detection configurations apply to all databases hosted on that server. In the Azure portal, this is configured under the Azure SQL server blade's 'Security' section, specifically in the 'Microsoft Defender for Cloud' pane, where you can enable 'Microsoft Defender for SQL' (which includes ATP). This ensures that all databases on the server inherit the protection, including vulnerability assessment and threat detection alerts.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.