AZ-500 Secure compute, storage, and databases Practice Question
Exhibit
Refer to the exhibit.
{
"type": "Microsoft.Sql/servers/databases/securityAlertPolicies",
"apiVersion": "2023-08-01-preview",
"properties": {
"state": "Enabled",
"emailAccountAdmins": true,
"emailAddresses": ["admin@contoso.com"],
"disabledAlerts": [],
"retentionDays": 30
}
}You are deploying an Azure SQL Database with a security alert policy as shown in the exhibit. Which statement is true?
⚠ Common exam trap
Watch out — candidates often assume an empty 'disabledAlerts' list means all alerts are disabled, but in Azure SQL Database, an empty list means no alerts are excluded, so all are enabled by default.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Alerts are enabled and notifications are sent to both account admins and admin@contoso.com.
The security alert policy in Azure SQL Database has 'state' set to 'Enabled' and 'emailAddresses' includes both 'admin@contoso.com' and the account admins (via 'emailAccountAdmins' set to true). This means alerts are active and notifications are sent to both the specified email and the account administrators, making option A correct.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Alerts are enabled and notifications are sent to both account admins and admin@contoso.com.
Why this is correct
This configuration is correct because the security alert policy has its state set to Enabled, meaning alerts are actively generated. With emailAccountAdmins set to true, all Azure subscription account administrators receive alert notifications, and since emailAddresses explicitly includes admin@contoso.com, that address is also notified. Thus alerts go to both account admins and the specified email address.
- ✗
Email notifications are sent only to admin@contoso.com.
Why it's wrong here
It claims notifications are sent only to admin@contoso.com, but the emailAccountAdmins property is true. That flag ensures the Azure account administrators (subscription/service admins) are also added to the notification list. Therefore, the recipient set includes account admins in addition to admin@contoso.com, so it is not the sole recipient.
- ✗
Alerts are not retained because retentionDays is set to 30.
Why it's wrong here
This option misinterprets retentionDays. A value of 30 indicates that alerts are retained for 30 days before they expire or are purged, not that alerts are not retained at all. Alert retention is separate from alert generation; state is Enabled here, and the retention period merely governs how long alert records are kept. Hence, alerts are still generated and stored for the configured duration.
- ✗
All alerts are disabled because disabledAlerts is empty.
Why it's wrong here
This option incorrectly assumes that an empty disabledAlerts array means all alerts are disabled. In reality, the disabledAlerts array specifies which alert types are turned off; an empty array means no alert types are disabled, so all alert types remain enabled. Since the policy state is Enabled and disabledAlerts is empty, all alerts are active, not disabled.
Go deeper
Related to this question
About these practice questions
This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.