DP-300 Plan and implement data platform resources Practice Question
You are deploying a new Azure SQL Database for an application that will store sensitive financial data. The compliance team requires that the database be configured to automatically detect and alert on anomalous access patterns, and that all queries be logged for auditing. Which services should you enable?
⚠ Common exam trap
Many candidates confuse Azure Defender for SQL with vulnerability assessment or Microsoft Sentinel, assuming a SIEM is required for detection, when Azure Defender for SQL already provides built-in anomaly detection for Azure SQL Database.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Azure Defender for SQL and SQL Auditing
Azure Defender for SQL provides anomaly detection and alerts for suspicious access patterns (e.g., SQL injection, brute force), while SQL Auditing captures all queries and events for compliance logging. Together, they meet the requirements for automatic detection and full query auditing without additional services.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Azure Purview and vulnerability assessment
Why it's wrong here
Purview catalogues and classifies data, and vulnerability assessment scans for misconfigurations; neither detects anomalous access patterns nor logs queries. Those requirements need Microsoft Defender for SQL and SQL Auditing. Purview and vulnerability assessment suit data governance and configuration hardening, not runtime threat detection.
- ✗
Microsoft Sentinel and SQL Auditing
Why it's wrong here
Microsoft Sentinel is a cloud SIEM ingesting logs from many sources; it does not natively detect anomalous access patterns on Azure SQL Database. That detection comes from Microsoft Defender for SQL, which also feeds alerts. Sentinel suits correlating security events across an estate once auditing data is already collected.
- ✓
Azure Defender for SQL and SQL Auditing
Why this is correct
Azure Defender for SQL provides threat detection and anomalous access alerts, while SQL Auditing writes query activity to a storage, Log Analytics, or Event Hub target. Together they satisfy both the detection-and-alert and query-logging compliance requirements.
- ✗
SQL Server auditing and vulnerability assessment
Why it's wrong here
Vulnerability assessment scans for configuration weaknesses, and SQL Server auditing logs events but does not detect anomalous access patterns. Anomaly detection requires Microsoft Defender for SQL. This pairing suits periodic configuration review and compliance logging, not the automatic behavioural alerting the compliance team demands.
Go deeper
Related to this question
Learn chapter
Securing Data at Rest and in Transit
Key term
Azure SQL Performance Tuning
Azure SQL Performance Tuning is the process of optimizing the speed and efficiency of queries and database operations in Microsoft Azure SQL Database or SQL Managed Instance to reduce latency and improve throughput.
About these practice questions
Courseiva writes every DP-300 question from scratch — 574 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DP-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-300 exam.