Courseiva
Question 397 of 981
Describe Azure architecture and servicesmediumMultiple ChoiceObjective-mapped

AZ-900 Describe Azure architecture and services Practice Question

Which Azure service provides automatic threat detection and response for Azure SQL Database, detecting anomalous activities like SQL injection?

⚠ Common exam trap

Watch out — candidates often confuse Azure SQL Database auditing (which only logs events) with threat detection, or they mistakenly think Azure Firewall can inspect SQL traffic at the application layer, but it only filters based on IP/port rules and cannot parse SQL syntax.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Microsoft Defender for SQL

Microsoft Defender for SQL is the correct answer because it is a cloud-native security solution specifically designed to detect and respond to threats against Azure SQL Database, including SQL injection attacks. It provides advanced threat protection by continuously monitoring database activities and generating security alerts for anomalous behaviors, such as unusual access patterns or injection attempts, without requiring manual intervention.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Azure SQL Database auditing

    Why it's wrong here

    Azure SQL Database auditing records database events, such as SELECT, INSERT, UPDATE, and permission changes, by writing them to an audit log for compliance and forensic purposes. It provides a trail of activity that can be reviewed after an incident, but it does not perform real-time analysis, anomaly detection, or generate security alerts on its own. Thus, auditing supports investigation but lacks the active threat detection needed to identify attacks as they happen.

  • Microsoft Defender for SQL

    Why this is correct

    Microsoft Defender for SQL is a cloud-native security solution that provides advanced threat protection, including vulnerability assessments and security alerts for Azure SQL databases and SQL servers on VMs. It continuously monitors database activity to detect SQL injection, brute-force attacks, and anomalous access patterns, then delivers actionable alerts with investigation steps. This makes it specifically designed for the database-level threat detection described in the scenario.

  • Azure Policy

    Why it's wrong here

    Azure Policy is a governance service that enforces rules on Azure resource configuration, such as allowed regions, resource types, or required tags, and can deny or modify non-compliant resources. It operates at the control plane, evaluating the state of resources, but it does not inspect database queries, connection patterns, or other data-plane runtime activity. Therefore, Azure Policy cannot identify a SQL injection or brute-force attempt against a database.

  • Azure Firewall

    Why it's wrong here

    Azure Firewall is a managed, stateful firewall that filters network traffic between Azure Virtual Networks and to/from the internet based on source/destination IPs, ports, and protocols. It protects the network perimeter by blocking malicious IP addresses or restricting open ports, but it sits outside the database engine and has no awareness of SQL query content or authentication attempts. As a result, it cannot detect database-specific threats like SQL injection, which occur at the application layer within the database service.

About these practice questions

Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Last reviewed: Jun 11, 2026

Question Discussion

Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.

Loading comments…

Sign in to join the discussion.

This AZ-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-900 exam.