AZ-500 Secure compute, storage, and databases Practice Question
Exhibit
Refer to the exhibit. ``` PS Azure:\> Get-AzSqlDatabaseAdvancedThreatProtectionSetting -ResourceGroupName RG1 -ServerName sqlsrv1 -DatabaseName db1 ResourceGroupName : RG1 ServerName : sqlsrv1 DatabaseName : db1 State : Disabled ```
You run the PowerShell cmdlet shown in the exhibit for an Azure SQL Database. What is the security implication?
⚠ Common exam trap
Many exam-takers confuse Vulnerability Assessment (which scans for misconfigurations and missing patches) with Advanced Threat Protection (which detects ongoing anomalous activities), leading them to overlook the specific security gap of missing anomaly detection.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The database is not protected against anomalous activities.
The cmdlet shown is `Set-AzSqlDatabaseVulnerabilityAssessmentSettings`, which enables Vulnerability Assessment (VA) but does not enable Advanced Threat Protection (ATP). Without ATP, the database lacks anomaly detection capabilities such as SQL injection detection, brute-force attack alerts, and unusual access pattern monitoring. Therefore, the database is not protected against anomalous activities, making option B correct.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Auditing of database queries is not configured.
Why it's wrong here
Azure SQL Database auditing records query and event logs for compliance and forensic analysis, while Advanced Threat Protection (ATP) is an independent security service that uses anomaly detection to identify threats. The PowerShell cmdlet in the exhibit returns only the ATP configuration state, not auditing settings, so the absence of auditing cannot be concluded from this output. Even if auditing were enabled, it would not provide the real-time anomalous-activity detection that ATP offers, making this option an incorrect explanation for why the database is vulnerable.
- ✓
The database is not protected against anomalous activities.
Why this is correct
The PowerShell cmdlet output indicates that Advanced Threat Protection is disabled on the Azure SQL Database. With ATP disabled, the service does not analyze database activity for anomalies such as SQL injection attempts, unusual access patterns, or brute-force attacks, leaving the database without this specific protective layer. This is the direct and accurate interpretation of the cmdlet result, as ATP is exactly the feature that protects against anomalous activities.
- ✗
The database firewall allows all public IP addresses.
Why it's wrong here
Azure SQL Database firewall rules are configured separately from threat protection settings and control network access to the database, not detection of anomalous activities. The cmdlet shown in the exhibit reports only the ATP state, so it provides no information about firewall rules, and allowing all public IP addresses would be a network exposure issue, not an anomaly-detection gap. ATP and firewall settings are independent security controls; a permissive firewall does not disable or reflect ATP's protection status.
- ✗
Transparent data encryption is not enabled.
Why it's wrong here
Transparent Data Encryption (TDE) is a separate security feature that encrypts data at rest, whereas Advanced Threat Protection (ATP) detects suspicious behavioral patterns during database access. The cmdlet output displays ATP status, not TDE status, so you cannot infer from it that TDE is disabled. Even if TDE were disabled, that would represent a storage-encryption deficiency, not a failure to protect against anomalous activities, making this option unrelated to the ATP state shown in the exhibit.
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.