Courseiva

DP-300 Plan and implement data platform resources Practice Question

You are deploying a new Azure SQL Database for an application that will store sensitive financial data. The compliance team requires that the database be configured to automatically detect and alert on anomalous access patterns, and that all queries be logged for auditing. Which services should you enable?

⚠ Common exam trap

Many candidates confuse Azure Defender for SQL with vulnerability assessment or Microsoft Sentinel, assuming a SIEM is required for detection, when Azure Defender for SQL already provides built-in anomaly detection for Azure SQL Database.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Azure Defender for SQL and SQL Auditing

Azure Defender for SQL provides anomaly detection and alerts for suspicious access patterns (e.g., SQL injection, brute force), while SQL Auditing captures all queries and events for compliance logging. Together, they meet the requirements for automatic detection and full query auditing without additional services.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Azure Purview and vulnerability assessment

    Why it's wrong here

    Purview catalogues and classifies data, and vulnerability assessment scans for misconfigurations; neither detects anomalous access patterns nor logs queries. Those requirements need Microsoft Defender for SQL and SQL Auditing. Purview and vulnerability assessment suit data governance and configuration hardening, not runtime threat detection.

  • ✗

    Microsoft Sentinel and SQL Auditing

    Why it's wrong here

    Microsoft Sentinel is a cloud SIEM ingesting logs from many sources; it does not natively detect anomalous access patterns on Azure SQL Database. That detection comes from Microsoft Defender for SQL, which also feeds alerts. Sentinel suits correlating security events across an estate once auditing data is already collected.

  • ✓

    Azure Defender for SQL and SQL Auditing

    Why this is correct

    Azure Defender for SQL provides threat detection and anomalous access alerts, while SQL Auditing writes query activity to a storage, Log Analytics, or Event Hub target. Together they satisfy both the detection-and-alert and query-logging compliance requirements.

  • ✗

    SQL Server auditing and vulnerability assessment

    Why it's wrong here

    Vulnerability assessment scans for configuration weaknesses, and SQL Server auditing logs events but does not detect anomalous access patterns. Anomaly detection requires Microsoft Defender for SQL. This pairing suits periodic configuration review and compliance logging, not the automatic behavioural alerting the compliance team demands.

About these practice questions

Courseiva writes every DP-300 question from scratch — 574 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DP-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-300 exam.