DP-300 Plan and implement data platform resources Practice Question
Your company has an Azure SQL Managed Instance that hosts multiple databases. You need to implement a solution to automatically detect and alert on potential SQL injection attacks. The solution must integrate with Microsoft Sentinel for incident response. What should you configure?
⚠ Common exam trap
A common mix-up: candidates confuse Microsoft Defender XDR (a broader security suite) with Microsoft Defender for SQL (the specific service for SQL threat detection), leading them to select Option B instead of the correct D.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable Microsoft Defender for SQL on the Managed Instance
Microsoft Defender for SQL on Azure SQL Managed Instance provides built-in SQL injection detection and alerting, which can be integrated directly with Microsoft Sentinel for automated incident response and investigation. This is the correct solution because it offers native vulnerability assessment and threat detection tailored to SQL databases, meeting the requirement for both detection and Sentinel integration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable Microsoft Purview Data Map for the Managed Instance
Why it's wrong here
Microsoft Purview Data Map catalogues and classifies data assets; it does not detect SQL injection attempts or forward alerts to Microsoft Sentinel. It is tempting because it does provide data security visibility, but it is the correct choice only for data governance and lineage, not runtime threat detection.
- ✗
Configure Microsoft Defender XDR for SQL
Why it's wrong here
Microsoft Defender XDR for SQL is a separate security portal; SQL Managed Instance threat detection with Microsoft Sentinel integration is delivered through Microsoft Defender for SQL, which streams alerts to the workspace. It is tempting because it does cover SQL threats, but it is the right choice only when Sentinel integration is not required.
- ✗
Use Microsoft Intune to manage SQL security policies
Why it's wrong here
Microsoft Intune manages device and application compliance policies; it has no capability to inspect SQL traffic or detect injection attempts on a Managed Instance. It is tempting because it does centralise security policy management, but it is the correct choice only for endpoint configuration, not database threat detection.
- ✓
Enable Microsoft Defender for SQL on the Managed Instance
Why this is correct
Microsoft Defender for SQL performs threat detection and advanced threat protection, raising alerts for anomalous activity such as SQL injection. Its alerts flow into Microsoft Defender for Cloud and can be streamed to Microsoft Sentinel for incident response.
Go deeper
Related to this question
Learn chapter
Deploying and Configuring Azure SQL Managed Instance
Key term
Azure SQL Threat Detection
Azure SQL Threat Detection is a built-in security feature that continuously monitors your Azure SQL database for suspicious activities and sends alerts when potential threats are found.
Key term
Azure SQL Managed Instance
Azure SQL Managed Instance is a fully managed cloud database service that gives you nearly all the features of Microsoft SQL Server on your own server, without you having to manage the hardware or operating system.
About these practice questions
Courseiva writes every DP-300 question from scratch — 574 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DP-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-300 exam.