Courseiva

AZ-500 Practice Question: Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel

Your organization uses Microsoft Defender for Cloud to protect Azure SQL databases. You receive a recommendation that 'SQL databases should have vulnerability findings resolved'. You run a vulnerability assessment scan and find a high-severity finding about a missing firewall rule. How should you resolve this finding?

⚠ Common exam trap

A common mix-up: candidates confuse vulnerability assessment findings with threat detection or auditing features, mistakenly thinking that enabling security monitoring (like ATP or Defender for SQL) will automatically fix configuration issues, when in fact the finding requires a direct network configuration change.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Add a firewall rule to the SQL server allowing traffic from the required IP addresses.

The vulnerability assessment finding about a missing firewall rule indicates that the SQL server is accessible from an overly broad range of IP addresses or lacks a necessary restriction. Adding a firewall rule to the SQL server that allows traffic only from the required IP addresses directly resolves the misconfiguration, reducing the attack surface. This aligns with the recommendation to remediate vulnerability findings by applying network access controls.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Change the SQL database auditing settings to capture all events.

    Why it's wrong here

    Changing the SQL database auditing settings to capture all events is a logging control, not a network security control. Azure SQL firewall rules are evaluated separately during connection establishment before any T-SQL executes, so expanded auditing cannot allow traffic blocked by the missing IP rule. It only creates audit records, which could support post-incident analysis but does not resolve the connectivity vulnerability.

  • ✓

    Add a firewall rule to the SQL server allowing traffic from the required IP addresses.

    Why this is correct

    Add a server-level firewall rule to the Azure SQL Server with the exact start and end IP addresses or CIDR range used by the application clients. By default Azure SQL blocks all external traffic; creating this rule explicitly permits those source IPs to connect while still denying all other ranges. This action directly addresses the Defender for Cloud finding that flagged missing firewall configuration.

  • ✗

    Enable Advanced Threat Protection for Azure SQL Database.

    Why it's wrong here

    Advanced Threat Protection for Azure SQL Database is a detection service that raises security alerts for suspicious activities like SQL injection, brute-force attempts, and anomalous access patterns. It operates after a connection attempt occurs and never mutates server-level firewall rules, so enabling it leaves the blocked source IPs unable to connect. The underlying network configuration issue remains until a firewall rule is created.

  • ✗

    Enable the 'Defender for SQL' plan on the server.

    Why it's wrong here

    Enabling the Defender for SQL plan on the server activates the broader Microsoft Defender for Cloud workload protection package, including vulnerability assessments and the SQL ATP features. This plan does not itself modify or add firewall rules, and existing Defender recommendations remain unresolved until the remediation bar is applied. It is a security monitoring and compliance capability, not a network access control, so the missing firewall rule persists.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.