Courseiva

Two Measures to Protect Azure SQL Database from SQL Injection Attacks

You need to protect Azure SQL Database from SQL injection attacks. Which TWO measures should you implement?

Quick Answer

The correct measures are using parameterized queries in application code and implementing a Web Application Firewall (WAF). Parameterized queries prevent SQL injection by strictly separating SQL code from user-supplied data, ensuring that input is always treated as data, never as executable commands. A WAF adds a critical layer of defense by inspecting and filtering malicious HTTP requests before they can reach your Azure SQL Database. On the AZ-500 exam, this question tests your understanding of application-layer security controls versus infrastructure-level protections; a common trap is confusing encryption features like Transparent Data Encryption (TDE) or Always Encrypted with injection prevention, but those only protect data at rest or in transit, not from malicious queries. To remember, think of the mnemonic "P-WAF": Parameterized queries handle the code, WAF handles the network traffic—together they block injection at both the app and perimeter layers.

⚠ Common exam trap

It's easy for candidates to confuse network-level controls (firewall rules) or encryption features (TDE, Always Encrypted) with application-layer defenses against SQL injection, leading them to select options that protect data confidentiality or access but do not prevent the injection attack itself.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implement Azure Web Application Firewall (WAF)

Option B (Azure Web Application Firewall) is correct because WAF, especially when deployed with Azure Application Gateway or Front Door, includes managed rule sets that detect and block common SQL injection patterns in HTTP requests before they reach the database. Option D (parameterized queries) is correct because parameterization separates SQL code from user-supplied data, so injected input is treated as a literal value rather than executable SQL, which is the most fundamental defense against SQL injection at the application layer. Option A (TDE) is not correct because it only encrypts data at rest and does nothing to prevent injection attacks. Option C (Azure SQL Database firewall rules) is not correct because it restricts access by IP address or Azure service, not by inspecting query content. Option E (Always Encrypted) is not correct because it protects sensitive column data from unauthorized viewing, not from SQL injection logic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable Transparent Data Encryption (TDE)

    Why it's wrong here

    TDE encrypts data at rest, protecting database files and backups from physical theft; it does not inspect or block malicious SQL statements. It is the right control for encryption-at-rest compliance. SQL injection requires input validation and parameterised queries, addressed by a web application firewall or Defender for SQL.

  • ✓

    Implement Azure Web Application Firewall (WAF)

    Why this is correct

    Azure Web Application Firewall inspects inbound HTTP/S requests and blocks known SQL injection signatures before they reach the database, satisfying the requirement to filter malicious payloads at the application edge rather than relying solely on database-side controls.

  • ✗

    Configure Azure SQL Database firewall rules

    Why it's wrong here

    Firewall rules restrict which IP addresses and networks may connect, so an attacker reaching the database through a permitted application path still executes injected SQL. Firewall rules suit blocking unauthorised source addresses. Injection defence needs query-level controls such as parameterised queries plus Defender for SQL threat detection.

  • ✓

    Use parameterized queries in application code

    Why this is correct

    Parameterised queries separate SQL code from user-supplied values, so injected input is treated as data and cannot alter query structure. This eliminates the injection vector at source, which WAF signature filtering alone cannot guarantee against obfuscated payloads.

  • ✗

    Enable Always Encrypted for sensitive columns

    Why it's wrong here

    Always Encrypted keeps sensitive column values encrypted end-to-end so the database engine never sees plaintext, but injected statements still execute against those columns. It is correct for protecting data from privileged DBAs. Injection prevention requires parameterised queries and a web application firewall, not column-level encryption.

About these practice questions

This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on AZ-500

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. You need to protect Azure SQL Database from SQL injection attacks. Which TWO measures should you implement? (Choose TWO.)

medium
  • A.Use Always Encrypted for sensitive columns.
  • ✓ B.Deploy Azure Web Application Firewall (WAF) in front of the application.
  • C.Enable Transparent Data Encryption (TDE).
  • D.Enable SQL Server auditing.
  • ✓ E.Use parameterized queries in application code.

Why B: Option B is correct because Azure Web Application Firewall (WAF), typically via Application Gateway or Front Door, inspects HTTP/HTTPS traffic and applies OWASP Core Rule Set rules that detect and block common SQL injection payloads before they reach the application or database. Option E is correct because parameterized queries (prepared statements) cause the database engine to treat user input strictly as data rather than executable SQL, which is the fundamental application-level defense against SQL injection. Option A is not correct here because Always Encrypted protects data confidentiality at rest and in memory by encrypting sensitive columns, but it does not detect or prevent SQL injection. Option C is not correct because Transparent Data Encryption (TDE) only encrypts data and log files at rest and has no bearing on injection attacks. Option D is not correct because SQL Server auditing records activity for compliance and forensic review after the fact; it is a detective control, not a preventive measure against SQL injection.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.