Courseiva

SC-100 Practice Question: Design security solutions for applications and data

A company uses Azure Cosmos DB with Microsoft Defender for Cloud to protect its NoSQL database. The security team wants to audit all data plane operations for compliance. Which diagnostic setting should they enable?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

DataPlaneRequests

The correct option is D, DataPlaneRequests. This diagnostic setting in Azure Cosmos DB logs all data plane operations, including CRUD actions on documents, which is exactly what the security team needs to audit for compliance. The other options do not fit: MongoRequests only captures requests for the MongoDB API, PartitionKeyStatistics provides metrics on partition key usage, and QueryRuntimeStatistics logs query execution details rather than a full audit of data plane operations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    MongoRequests

    Why it's wrong here

    MongoRequests captures only MongoDB wire protocol requests (e.g., find, insert, update, delete) issued against the Cosmos DB MongoDB API. It does not include requests made through the SQL API, Cassandra API, Gremlin API, or Table API, nor does it capture account-level metadata operations. As a result, it is far too narrow to serve as a comprehensive source for full data plane operation auditing.

  • ✗

    PartitionKeyStatistics

    Why it's wrong here

    PartitionKeyStatistics is a diagnostic telemetry category that reports logical partition key distribution, storage consumption, throughput utilization, and potential hot-partition indicators. It does not log individual data plane operations such as CRUD requests, nor does it contain operation-level metadata like request timestamps, user identity, or status codes. This makes it useful for capacity planning and partition design, but completely inappropriate for operational or security auditing.

  • ✗

    QueryRuntimeStatistics

    Why it's wrong here

    QueryRuntimeStatistics records performance metrics for query executions, such as request units (RU) consumed, duration, index hit vs. miss ratio, and number of documents scanned. It only applies to query operations and is not generated for point reads, creates, updates, deletes, or upserts. Therefore, it cannot be used to audit the full range of data plane operations, only a subset of read/query telemetry.

  • ✓

    DataPlaneRequests

    Why this is correct

    DataPlaneRequests is the diagnostic log that records every data plane request against an Azure Cosmos DB account, regardless of the API in use (SQL, MongoDB, Cassandra, Gremlin, Table). Each entry includes the operation type (e.g., create, read, upsert, delete, query), resource URI, partition key range, current status code, request charge, client IP, and authentication token type. This comprehensive coverage of all CRUD and other data operations makes it the correct source for auditing and forensic analysis of data plane activity.

About these practice questions

Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.