DP-300 Implement a secure environment Practice Question
You need to audit all successful and failed login attempts to an Azure SQL Database. Which feature should you enable?
⚠ Common exam trap
Many candidates confuse Advanced Threat Protection's alerting on suspicious logins with the comprehensive logging of all login attempts provided by Azure SQL Auditing, leading them to select ATP instead.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Azure SQL Auditing
Azure SQL Auditing is the correct feature because it tracks database events, including both successful and failed login attempts, and writes them to an audit log in your Azure Storage account, Log Analytics workspace, or Event Hubs. This allows you to monitor and review authentication activity for compliance and security analysis. Other features like Advanced Threat Protection, TDE, and Vulnerability Assessment do not capture login event logs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Azure SQL Auditing
Why this is correct
Azure SQL Auditing captures both successful and failed authentication attempts, plus the originating IP and user, writing them to a storage account, Log Analytics workspace, or Event Hubs. This directly satisfies the requirement to audit all login attempts.
- ✗
Advanced Threat Protection
Why it's wrong here
Advanced Threat Protection detects anomalous activity such as SQL injection and brute-force patterns, and raises alerts — it does not record every successful and failed login attempt. Auditing, which writes login events to the audit log, is the feature that captures both outcomes. ATP would be chosen when the requirement is threat detection rather than a full authentication record.
- ✗
Transparent Data Encryption (TDE)
Why it's wrong here
Transparent Data Encryption encrypts data at rest, protecting database, log, and backup files; it records no authentication events. Auditing is what captures successful and failed login attempts. TDE would be the correct choice when the requirement is encryption of stored data or compliance for data-at-rest protection, not login tracking.
- ✗
SQL Vulnerability Assessment
Why it's wrong here
SQL Vulnerability Assessment scans database configuration and schema against security baselines, producing findings and remediation guidance; it does not log individual login attempts. Auditing writes those events. Vulnerability Assessment would be correct when the requirement is identifying misconfigurations and weaknesses rather than recording authentication activity.
Go deeper
Related to this question
Learn chapter
Implementing Auditing and Threat Detection
Key term
Azure SQL Auditing
Azure SQL Auditing is a feature that tracks and records database events, such as data changes and logins, and writes them to an audit log for security monitoring and compliance.
Key term
Transparent Data Encryption
Transparent Data Encryption is a security feature that automatically encrypts data written to a database and decrypts it when read, without requiring any changes to the application.
About these practice questions
Courseiva writes every DP-300 question from scratch — 574 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DP-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-300 exam.