Courseiva
Implement a secure environmentmediumMultiple ChoiceObjective-mapped

DP-300 Implement a secure environment Practice Question

You are configuring Microsoft Defender for SQL for Azure SQL Database. You need to ensure that alerts are sent to the security operations team via email and also integrated with Microsoft Sentinel. What should you configure?

⚠ Common exam trap

It's easy for candidates to confuse diagnostic settings (which stream performance and query logs) with the dedicated Sentinel connector (which ingests security alerts), leading them to choose Option C, or they overcomplicate the solution by selecting Logic Apps (Option B) when a native connector already exists.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

In Microsoft Sentinel, connect the Azure SQL Database data source using the built-in connector.

Microsoft Sentinel provides a built-in connector for Azure SQL Database that ingests security alerts from Microsoft Defender for SQL, satisfying the Sentinel integration requirement. The email notification requirement is addressed separately by configuring alert rules within Defender for SQL to send emails to the security operations team. Option A enables the Sentinel integration, while email notifications are a complementary configuration within Defender for SQL, not part of Option A itself.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • In Microsoft Sentinel, connect the Azure SQL Database data source using the built-in connector.

    Why this is correct

    Sentinel has a built-in connector for Azure SQL Database that pulls alerts from Defender for SQL.

  • Use Azure Logic Apps to forward Defender for SQL alerts to Sentinel.

    Why it's wrong here

    Logic Apps can be used but the direct method is a data connector in Sentinel.

  • Configure a diagnostic setting on the SQL server to stream logs to a Log Analytics workspace used by Sentinel.

    Why it's wrong here

    Diagnostic settings stream resource logs, but Defender for SQL alerts are not included in those logs.

  • Configure the alert rule in Defender for SQL to send email to the security team.

    Why it's wrong here

    Email notifications are configured in Defender for SQL, but this alone does not integrate with Sentinel.

About these practice questions

This DP-300 question is part of Courseiva's 906-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DP-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-300 exam.