SC-100 Practice Question: Design security solutions for applications and data
Your organization uses Microsoft Sentinel to centralize security monitoring. You need to detect anomalous access to a critical Azure SQL Database from unusual geographic locations. Which data connector and analytic rule should you use?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Azure SQL Database connector and a custom scheduled query rule with geo-location
The correct option is A: Azure SQL Database connector and a custom scheduled query rule with geo-location. The Azure SQL Database connector ingests SQL audit and diagnostic logs into Microsoft Sentinel, which include client IP addresses, so a custom scheduled analytics rule can parse those IPs, enrich them with geo-location data (e.g., via the GeoIP watchlist or built-in functions), and alert on access from unusual regions. Option B does not fit because Microsoft Entra ID sign-in anomaly rules cover identity authentication events, not direct database access. Option C is wrong because Windows Security Events cover OS-level logons on Windows hosts, not Azure SQL Database access. Option D is wrong because Azure Activity logs track control-plane operations like resource deletion, not data-plane SQL connections.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Azure SQL Database connector and a custom scheduled query rule with geo-location
Why this is correct
The Azure SQL Database connector ingests diagnostic telemetry such as SQLInsights and QueryStoreRuntimeStatistics, which include the client IP address for every connection. A custom scheduled query rule can run KQL to map these IPs to geographic locations (using the GeoIP enrichment or a watchlist) and alert when a connection originates from a country that is abnormal for your environment. This directly captures data-plane connection attempts to Azure SQL, so it is the correct pairing of source and detection logic.
- ✗
Microsoft Entra ID connector and an anomaly rule for sign-ins
Why it's wrong here
The Microsoft Entra ID connector and its sign-in anomaly rule examine authentication events against the Entra ID tenant, such as user login from a new device or unusual location. However, Azure SQL Database connections do not necessarily produce Microsoft Entra ID sign-in logs—especially when using SQL authentication rather than Microsoft Entra authentication—and successful connections are not sign-in events at all. A rule based on Microsoft Entra ID sign-ins would miss anonymous or SQL-authenticated database logins and therefore cannot reliably detect a threat actor connecting directly to the database from a strange IP.
- ✗
Windows Security Events connector and a rule for failed logins
Why it's wrong here
Windows Security Events (Event ID 4625, for example) are produced by the Windows operating system on local machines and Azure IaaS virtual machines, not by the fully managed Azure SQL Database service. Azure SQL Database does not write to Windows security logs; instead, it writes audit records to a database-level audit log or streams diagnostics (such as SQLSecurityAuditEvents) to Log Analytics. A rule on failed Windows logins would only detect OS login failures on VM or on-premises hosts, so it would completely miss unauthorized SQL connections from unusual locations.
- ✗
Azure Activity connector and a rule for resource deletion
Why it's wrong here
The Azure Activity connector captures control-plane operations through Azure Resource Manager, such as creating, deleting, or scaling a database, and it records the actor who performed the management action. A connection to the database from an odd IP is a data-plane event that is not logged in the Activity Log, because the Activity Log does not include SQL connection attempts, queries, or failed logins. Therefore, a rule monitoring resource deletion would never see the geo-location of a database connection, making it an inappropriate detection strategy.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.