Courseiva

DP-300 Plan and implement data platform resources Practice Question

Your company has an Azure SQL Managed Instance that hosts multiple databases. You need to implement a solution to automatically detect and alert on potential SQL injection attacks. The solution must integrate with Microsoft Sentinel for incident response. What should you configure?

⚠ Common exam trap

A common mix-up: candidates confuse Microsoft Defender XDR (a broader security suite) with Microsoft Defender for SQL (the specific service for SQL threat detection), leading them to select Option B instead of the correct D.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable Microsoft Defender for SQL on the Managed Instance

Microsoft Defender for SQL on Azure SQL Managed Instance provides built-in SQL injection detection and alerting, which can be integrated directly with Microsoft Sentinel for automated incident response and investigation. This is the correct solution because it offers native vulnerability assessment and threat detection tailored to SQL databases, meeting the requirement for both detection and Sentinel integration.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable Microsoft Purview Data Map for the Managed Instance

    Why it's wrong here

    Microsoft Purview Data Map catalogues and classifies data assets; it does not detect SQL injection attempts or forward alerts to Microsoft Sentinel. It is tempting because it does provide data security visibility, but it is the correct choice only for data governance and lineage, not runtime threat detection.

  • ✗

    Configure Microsoft Defender XDR for SQL

    Why it's wrong here

    Microsoft Defender XDR for SQL is a separate security portal; SQL Managed Instance threat detection with Microsoft Sentinel integration is delivered through Microsoft Defender for SQL, which streams alerts to the workspace. It is tempting because it does cover SQL threats, but it is the right choice only when Sentinel integration is not required.

  • ✗

    Use Microsoft Intune to manage SQL security policies

    Why it's wrong here

    Microsoft Intune manages device and application compliance policies; it has no capability to inspect SQL traffic or detect injection attempts on a Managed Instance. It is tempting because it does centralise security policy management, but it is the correct choice only for endpoint configuration, not database threat detection.

  • ✓

    Enable Microsoft Defender for SQL on the Managed Instance

    Why this is correct

    Microsoft Defender for SQL performs threat detection and advanced threat protection, raising alerts for anomalous activity such as SQL injection. Its alerts flow into Microsoft Defender for Cloud and can be streamed to Microsoft Sentinel for incident response.

Go deeper

Related to this question

About these practice questions

Courseiva writes every DP-300 question from scratch — 574 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DP-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-300 exam.