AZ-500 Practice Question: Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel
Which TWO are features of Microsoft Defender for Cloud's workload protection for Azure SQL databases? (Select two.)
⚠ Common exam trap
It's easy for candidates to confuse workload protection features that apply broadly to VMs (like FIM, Adaptive Network Hardening, and JIT VM Access) with those specifically designed for PaaS services like Azure SQL, leading them to select options that are not applicable to databases.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Advanced threat protection (ATP)
Option D (Advanced threat protection/ATP) is correct because Microsoft Defender for Cloud's workload protection for Azure SQL databases includes Defender for SQL's advanced threat protection, which detects anomalous activities such as potential SQL injection, brute-force attempts, and unusual access patterns, and raises security alerts. Option E (Vulnerability assessment) is correct because Defender for SQL provides a built-in vulnerability assessment that scans Azure SQL databases for misconfigurations, missing security updates, and other weaknesses, with findings surfaced in Defender for Cloud. Option A (File integrity monitoring) is not correct here because FIM applies to files and registry keys on servers/VMs (via Defender for Servers/Log Analytics), not to Azure SQL database workload protection. Option B (Adaptive network hardening) is not correct because it is a Defender for Cloud feature for virtual machines that analyzes network security group rules and traffic patterns, not a SQL database protection feature. Option C (Just-in-time VM access) is not correct because JIT VM access is a Defender for Servers capability that locks down management ports on VMs, not an Azure SQL database workload protection feature.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
File integrity monitoring (FIM)
Why it's wrong here
File integrity monitoring (FIM) in Microsoft Defender for Cloud examines operating system files, Windows registries, and application software on virtual machines and physical servers, not on PaaS SQL databases. It detects unauthorized modifications to these file-level artifacts, but it cannot assess SQL-specific threats such as anomalous query patterns or SQL injection. Therefore, FIM is outside the scope of Defender for SQL's workload protections.
- ✗
Adaptive network hardening
Why it's wrong here
Adaptive network hardening hardens virtual machine network security groups by analyzing legitimate traffic flows and then proposing tightened NSG rules to reduce brute-force exposure on management ports. This capability applies to IaaS networking infrastructure, not to Azure SQL Database or SQL Managed Instance. Because the question asks about SQL workload features, adaptive network hardening is an incorrect alternative.
- ✗
Just-in-time VM access
Why it's wrong here
Just-in-time VM access restricts the time window during which management ports such as RDP and SSH are open on Azure VMs, requiring authorization before a port is opened. Its purpose is to shrink the VM attack surface, and it has no effect on SQL database authentication or query activities. Thus, JIT is an unrelated security control for compute resources rather than a Defender for SQL feature.
- ✓
Advanced threat protection (ATP)
Why this is correct
Advanced threat protection (ATP) for Azure SQL is a built-in feature of Microsoft Defender for SQL that continuously monitors database activity for unusual access patterns, suspicious location changes, and potential SQL injection attempts. It generates security alerts for anomalies such as a user accessing the database from an unfamiliar IP address or an attempt to enumerate credentials. This makes ATP a correct choice because it directly protects SQL database workload.
- ✓
Vulnerability assessment
Why this is correct
Vulnerability assessment in Defender for SQL runs periodic scans of the database and compares its configuration and permissions against a baseline of security best practices. It reports issues like missing firewall rules, over-privileged accounts, or known misconfigurations, and supplies remediation steps. As one of the core components of Defender for SQL, it is correctly identified as a feature for SQL workloads.
Go deeper
Related to this question
About these practice questions
One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.