Courseiva

DP-300 Implement a secure environment Practice Question

You need to protect Azure SQL Database from SQL injection attacks. Which THREE of the following measures should you implement?

⚠ Common exam trap

Test-takers frequently confuse data protection features like dynamic data masking or TDE with SQL injection prevention, when in fact they address entirely different threats (data exposure at query time vs. data at rest encryption).

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable Microsoft Defender for SQL to detect and alert on SQL injection.

Option A is correct because Microsoft Defender for SQL provides advanced threat protection that specifically detects anomalous and potentially harmful activities such as SQL injection attempts against Azure SQL Database, generating alerts and recommendations. Option B is correct because parameterized queries and stored procedures ensure that user input is treated as data rather than executable SQL code, which is the fundamental application-level defense against SQL injection. Option D is correct because an Azure Web Application Firewall (WAF), for example on Application Gateway or Front Door, inspects HTTP/HTTPS traffic and blocks common injection patterns before they reach the application and database. Option C is not correct because dynamic data masking only obscures sensitive data in query results for unauthorized users; it does not prevent or detect SQL injection. Option E is not correct because Transparent Data Encryption protects data at rest by encrypting database files, but it does not stop SQL injection, which exploits the application's query logic rather than the storage layer.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Enable Microsoft Defender for SQL to detect and alert on SQL injection.

    Why this is correct

    Microsoft Defender for SQL provides threat detection that identifies anomalous and injection-like query patterns against the database, raising alerts for investigation. It adds a detection layer that complements input validation and query parameterisation, forming part of a layered defence.

  • ✓

    Use parameterized queries or stored procedures in the application.

    Why this is correct

    Parameterised queries and stored procedures separate SQL code from user-supplied values, so injected input is treated as data rather than executable statements. This eliminates the primary injection vector at the application layer, before queries reach the database.

  • ✗

    Implement dynamic data masking to hide sensitive data from unauthorized users.

    Why it's wrong here

    Dynamic data masking hides column values in query results but does not stop injected SQL from executing or altering data. It is tempting because it is a genuine security feature, and it would be correct when the requirement is limiting exposure of sensitive data to non-privileged users rather than preventing injection.

  • ✓

    Use a web application firewall (WAF) in front of the application to filter malicious inputs.

    Why this is correct

    A web application firewall inspects inbound HTTP requests and blocks common injection payloads before they reach the application, adding a perimeter filtering layer. It reduces the attack surface but must be combined with parameterised queries for defence in depth.

  • ✗

    Enable Transparent Data Encryption (TDE) to encrypt the database at rest.

    Why it's wrong here

    TDE encrypts data and backups at rest; it does not inspect or block malicious SQL statements, so injection still executes. It is tempting because it is a core database security control, and it would be correct when the requirement is compliance-driven encryption of stored data rather than input validation.

Go deeper

Related to this question

About these practice questions

This DP-300 question is part of Courseiva's 574-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DP-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-300 exam.