AZ-500 Secure compute, storage, and databases Practice Question
You need to ensure that Azure SQL Database automatically detects and alerts on potential SQL injection attacks. Which Microsoft Defender for Cloud plan should you enable?
⚠ Common exam trap
Candidates often confuse Microsoft Defender for Cloud's free tier with the paid plans, assuming basic threat detection is included, or they mistakenly think Defender for App Service covers database-level threats, when in fact only Defender for SQL provides the specific SQL injection detection for Azure SQL Database.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Defender for SQL
Microsoft Defender for SQL includes advanced SQL security features such as Vulnerability Assessment, Advanced Threat Protection, and Data Discovery & Classification. Specifically, its Advanced Threat Protection capability uses machine learning models to detect anomalous database activities, including SQL injection attempts, and can trigger alerts or automated responses. Enabling this plan on your Azure SQL Database ensures that potential SQL injection attacks are automatically detected and alerted.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Microsoft Defender for SQL
Why this is correct
Microsoft Defender for SQL is the security plan that specifically protects Azure SQL Database, SQL Managed Instance, and Azure Synapse SQL. When enabled, it automatically monitors SQL audit logs for suspicious activities such as SQL injection, brute-force login attempts, and anomalous data exfiltration, generating security alerts in Microsoft Defender for Cloud. This is the direct service needed to satisfy the requirement for automatic threat detection on Azure SQL Database.
- ✗
Microsoft Defender for Storage
Why it's wrong here
Microsoft Defender for Storage monitors Azure Blob Storage, Azure Files, and Azure Data Lake Storage for anomalies like unusual access patterns, premature file deletion, and potential malware in uploaded files. It has no visibility into SQL Server query execution, database login logs, or SQL audit events, so it cannot detect SQL injection or other database-specific threats. Enabling this plan would leave Azure SQL Database completely unprotected.
- ✗
Microsoft Defender for Cloud (free tier)
Why it's wrong here
The free tier of Microsoft Defender for Cloud (now foundational CSPM) provides continuous assessment of security posture through recommendations, secure score, and compliance checks, but it does not include runtime threat detection or advanced anomaly monitoring. It may alert you to the fact that Defender for SQL is not enabled, yet it will not automatically inspect SQL traffic or audit logs for malicious activity. Therefore free tier alone cannot ensure automatic detection of threats to an Azure SQL database.
- ✗
Microsoft Defender for App Service
Why it's wrong here
Microsoft Defender for App Service is a workload protection plan for web apps, APIs, and functions hosted on Azure App Service. It detects attacks against the application layer, such as exposed administrative interfaces, brute-force attempts on the web app, and indicators of compromised app containers, by analyzing App Service logs and traffic. Since this plan has no integration with SQL audit logs or database query execution, it cannot monitor Azure SQL Database for database-specific nefarious activity.
Go deeper
Related to this question
About these practice questions
This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.