Courseiva

AZ-500 Secure compute, storage, and databases Practice Question

Your company uses Azure SQL Database. You need to ensure that all queries are audited for compliance. Which feature should you enable?

⚠ Common exam trap

Test-takers frequently confuse security monitoring features (like Advanced Threat Protection or Vulnerability Assessment) with the specific auditing capability required to log all queries for compliance, leading them to select a feature that detects threats rather than records query history.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable SQL Auditing on the server and configure the audit log destination.

To audit all queries against Azure SQL Database for compliance, you must enable SQL Auditing at the server level and configure an audit log destination (such as Azure Storage, Log Analytics, or Event Hubs). This captures database events, including all queries, and writes them to the chosen destination for review and retention. Option B directly fulfills the requirement to track and log query activity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable SQL Vulnerability Assessment.

    Why it's wrong here

    SQL Vulnerability Assessment (VA) identifies security misconfigurations, missing patches, and deviations from security best practices by comparing the database schema against a known baseline. It produces a compliance and risk report, but it does not capture, record, or stream query activity, so it cannot serve as an audit trail. VA is a reactive assessment tool, not a logging mechanism, and therefore fails to meet the stated requirement.

  • ✓

    Enable SQL Auditing on the server and configure the audit log destination.

    Why this is correct

    SQL Auditing in Azure SQL Database tracks database events at the server or database level and writes them to a configurable destination such as Azure Storage, Log Analytics, or Event Hubs. By enabling it, you can capture exact T-SQL statements, the principal executing them, timestamps, and success/failure status, effectively logging queries for forensic and compliance purposes. The audit log can be customized via audit action groups to include SELECT, INSERT, UPDATE, DELETE, and other data operations, making this the only option that directly provides query-level logging.

  • ✗

    Configure Dynamic Data Masking.

    Why it's wrong here

    Dynamic Data Masking limits exposure of sensitive data by presenting masked values to non-privileged users in query results, while leaving the underlying data intact in the database. It is a data protection feature that prevents unauthorized viewing of columns like credit card numbers or emails, but it does not record who ran a query, when it was run, or what the query was. Therefore, while it reduces data exposure, it does not create an audit trail and is not a substitute for query logging.

  • ✗

    Enable Advanced Threat Protection.

    Why it's wrong here

    Advanced Threat Protection (ATP) for Azure SQL Database continuously monitors for suspicious activities, such as SQL injection attempts, anomalous access patterns, and potential brute-force attacks, then generates security alerts for investigation. It is an intelligent threat detection service that provides real-time alerts, but it does not log every query or maintain a comprehensive query audit history. ATP complements auditing by identifying threats, but it does not offer the granular, retroactive logging needed to track all queries.

About these practice questions

This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.