AZ-500 Practice Question: Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel
Your organization uses Microsoft Defender for Cloud's workload protection for Azure SQL databases. You notice that Defender for Cloud is not generating alerts for anomalous activities on a specific SQL database. The database is in a VNet with a service endpoint enabled for SQL. What should you verify first?
⚠ Common exam trap
A common mix-up: candidates assume network-level controls (like service endpoints or firewall rules) are the root cause for missing alerts, when the actual requirement is enabling the threat detection feature (ATP) at the server level.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable Advanced Threat Protection on the Azure SQL Server.
Defender for Cloud's workload protection for Azure SQL databases relies on Advanced Threat Protection (ATP) being enabled at the Azure SQL Server level. Without ATP enabled, Defender for Cloud cannot generate alerts for anomalous activities, regardless of network configurations like VNet service endpoints. Enabling ATP activates the threat detection engine that monitors SQL audit logs for suspicious patterns.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Ensure the service endpoint is configured correctly.
Why it's wrong here
Service endpoints are a network security feature that restricts Azure SQL Server connectivity to selected virtual network subnets, which helps prevent data exfiltration but does not enable any security monitoring. Microsoft Defender for Cloud's Advanced Threat Protection for Azure SQL is a control-plane capability that generates alerts from telemetry analyzed by Microsoft's security intelligence, not from inbound SQL traffic. Consequently, even a misconfigured service endpoint would not prevent the loss of ATP alerts and adjusting it cannot trigger or restore SQL-specific anomaly detection.
- ✓
Enable Advanced Threat Protection on the Azure SQL Server.
Why this is correct
Advanced Threat Protection (ATP) for Azure SQL Server (also known as Defender for SQL) must be enabled at the server level; it activates vulnerability assessment, anomaly detection, and the alerting engine that surface suspicious activities like SQL injection, brute-force attempts, or unusual access patterns. When ATP is on, Microsoft Defender for Cloud automatically collects and displays these SQL-specific security alerts in its alerts pane. Without ATP enabled, no anomaly-based SQL alert will ever appear in Defender for Cloud, regardless of auditing, firewalls, or service endpoints.
- ✗
Enable auditing on the SQL database.
Why it's wrong here
Auditing tracks database events and writes them to an audit log destination such as Azure Storage or Log Analytics for compliance and forensic review, but it is a passive logging mechanism that does not analyze events in real time. The Advanced Threat Protection engine for SQL uses its own behavioral analytics and machine-learning detectors, not audit logs, to generate security alerts. Therefore, enabling auditing is not required for anomaly detection and will not cause ATP alerts to appear in Defender for Cloud if ATP itself is disabled.
- ✗
Configure a firewall rule to allow Defender for Cloud IP addresses.
Why it's wrong here
Microsoft Defender for Cloud does not reach into your Azure SQL database through a client-facing IP firewall rule; its SQL threat detection operates in the Azure control plane and consumes telemetry from the service, so no Defender for Cloud IP address needs to be allowlisted. The SQL firewall controls which client IP addresses can open TDS connections and is irrelevant to the ATP alerting pipeline. Adding a rule to allow Defender for Cloud's IP addresses would not only fail to generate alerts but could also create unnecessary network exposure.
Go deeper
Related to this question
About these practice questions
One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.