Courseiva

DP-300 Implement a secure environment Practice Question

You are responsible for security compliance of Azure SQL databases. You need to audit all successful and failed login attempts and store the audit logs in a Log Analytics workspace for analysis. You also want to detect potential brute-force attacks. What should you implement?

⚠ Common exam trap

Many candidates confuse Advanced Threat Protection (ATP) with the combination of auditing and Sentinel, assuming ATP alone covers login auditing and brute-force detection, but ATP does not capture all login attempts nor store them in Log Analytics for custom analysis.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable Azure SQL Auditing for the server, configure the audit log destination to Log Analytics, and enable Microsoft Sentinel for threat detection.

Azure SQL Auditing captures both successful and failed login attempts (audit logs) and can be configured to send them directly to a Log Analytics workspace for centralized analysis. Microsoft Sentinel, when enabled, provides built-in analytics rules to detect brute-force attacks by correlating failed login patterns across time and IP addresses, fulfilling the threat detection requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure Azure Policy to enforce auditing on all SQL databases in the subscription.

    Why it's wrong here

    Azure Policy enforces configuration compliance across a subscription; it cannot capture login success and failure events or route them to a Log Analytics workspace. It is tempting because it governs auditing settings at scale, which suits standardising configuration, not collecting and analysing authentication telemetry.

  • ✗

    Enable SQL Vulnerability Assessment and schedule recurring scans.

    Why it's wrong here

    Vulnerability Assessment scans database configuration and schema for weaknesses on a schedule; it does not record individual login successes and failures or forward them to a Log Analytics workspace. It is tempting because it addresses security posture, and would be correct if the requirement were identifying misconfigurations rather than auditing sign-in activity.

  • ✓

    Enable Azure SQL Auditing for the server, configure the audit log destination to Log Analytics, and enable Microsoft Sentinel for threat detection.

    Why this is correct

    Server-level Azure SQL Auditing captures successful and failed logins, and routing those records to a Log Analytics workspace enables querying. Microsoft Sentinel then correlates the ingested data to detect brute-force patterns, satisfying both the auditing and threat-detection requirements.

  • ✗

    Enable Advanced Threat Protection (ATP) for Azure SQL Database.

    Why it's wrong here

    Advanced Threat Protection raises alerts on anomalous patterns such as brute-force attempts, but it does not itself write the full stream of successful and failed login audit records to a Log Analytics workspace. It is tempting because threat detection is genuinely its purpose, and it would be correct if alerting alone were required.

Go deeper

Related to this question

About these practice questions

This DP-300 question is part of Courseiva's 574-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DP-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-300 exam.