Courseiva

AZ-500 Practice Question: Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel

Your organization uses Microsoft Defender for Cloud to monitor Azure SQL databases. You receive an alert indicating a potential SQL injection attack. What is the most effective immediate action to validate and respond?

⚠ Common exam trap

Watch out — candidates often confuse reactive forensic actions (like reviewing audit logs) with proactive security controls (like TDE or vulnerability assessments), or they assume that blocking IPs is the immediate best practice without first validating the attack through logs, which is a common mistake in incident response scenarios.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Review the SQL database auditing logs to identify the source queries

SQL database auditing logs capture detailed information about database events, including the exact SQL queries executed against the database. Reviewing these logs allows you to identify the source queries, the originating IP addresses, and the user accounts involved in the suspected SQL injection attack, enabling you to validate the alert and take targeted remediation actions. This is the most effective immediate step to confirm the attack and understand its scope before implementing broader security controls.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable Transparent Data Encryption (TDE) on the database

    Why it's wrong here

    TDE performs real-time I/O encryption and decryption of data and log files at rest, but it does not provide visibility into query patterns or authenticate whether an alert is a true positive. Enabling TDE would not help confirm or investigate the source of a suspected attack; it only protects against offline theft of physical media. For validating an active alert, you need audit logs or query insights.

  • ✗

    Run a vulnerability assessment on the database

    Why it's wrong here

    Vulnerability assessment scans the database for security misconfigurations, missing patches, and known vulnerabilities, but it is a point-in-time scan, not a real-time monitoring tool. It cannot identify the specific queries or source IPs associated with a current Defender alert. While it may help remediate underlying weaknesses, it does not provide forensic details to validate an active attack.

  • ✓

    Review the SQL database auditing logs to identify the source queries

    Why this is correct

    SQL database auditing tracks database events and writes them to an audit log in Azure Storage, Log Analytics, or Event Hub. Reviewing these logs lets you see the exact queries, the principal/user, the source IP address, and the timestamp of the suspicious activity, confirming whether the Defender alert is a genuine attack and revealing its origin. This is the direct and immediate way to validate an alert from Microsoft Defender for Cloud.

  • ✗

    Immediately block all IP addresses from the alert in the SQL firewall

    Why it's wrong here

    Immediately blocking all IP addresses listed in the alert would deny access to all clients, including legitimate applications and users, effectively causing a denial of service. The alert may include a mix of benign and malicious addresses, and blocking them all without investigation could disrupt business operations. You should first examine audit logs to confirm the malicious source IPs, then apply targeted firewall rules to block only those addresses.

About these practice questions

One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.