Courseiva

SC-100 Practice Question: Design security solutions for applications and data

Your organization uses Microsoft Sentinel to centralize security monitoring. You need to detect anomalous access to a critical Azure SQL Database from unusual geographic locations. Which data connector and analytic rule should you use?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Azure SQL Database connector and a custom scheduled query rule with geo-location

The correct option is A: Azure SQL Database connector and a custom scheduled query rule with geo-location. The Azure SQL Database connector ingests SQL audit and diagnostic logs into Microsoft Sentinel, which include client IP addresses, so a custom scheduled analytics rule can parse those IPs, enrich them with geo-location data (e.g., via the GeoIP watchlist or built-in functions), and alert on access from unusual regions. Option B does not fit because Microsoft Entra ID sign-in anomaly rules cover identity authentication events, not direct database access. Option C is wrong because Windows Security Events cover OS-level logons on Windows hosts, not Azure SQL Database access. Option D is wrong because Azure Activity logs track control-plane operations like resource deletion, not data-plane SQL connections.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Azure SQL Database connector and a custom scheduled query rule with geo-location

    Why this is correct

    The Azure SQL Database connector ingests diagnostic telemetry such as SQLInsights and QueryStoreRuntimeStatistics, which include the client IP address for every connection. A custom scheduled query rule can run KQL to map these IPs to geographic locations (using the GeoIP enrichment or a watchlist) and alert when a connection originates from a country that is abnormal for your environment. This directly captures data-plane connection attempts to Azure SQL, so it is the correct pairing of source and detection logic.

  • ✗

    Microsoft Entra ID connector and an anomaly rule for sign-ins

    Why it's wrong here

    The Microsoft Entra ID connector and its sign-in anomaly rule examine authentication events against the Entra ID tenant, such as user login from a new device or unusual location. However, Azure SQL Database connections do not necessarily produce Microsoft Entra ID sign-in logs—especially when using SQL authentication rather than Microsoft Entra authentication—and successful connections are not sign-in events at all. A rule based on Microsoft Entra ID sign-ins would miss anonymous or SQL-authenticated database logins and therefore cannot reliably detect a threat actor connecting directly to the database from a strange IP.

  • ✗

    Windows Security Events connector and a rule for failed logins

    Why it's wrong here

    Windows Security Events (Event ID 4625, for example) are produced by the Windows operating system on local machines and Azure IaaS virtual machines, not by the fully managed Azure SQL Database service. Azure SQL Database does not write to Windows security logs; instead, it writes audit records to a database-level audit log or streams diagnostics (such as SQLSecurityAuditEvents) to Log Analytics. A rule on failed Windows logins would only detect OS login failures on VM or on-premises hosts, so it would completely miss unauthorized SQL connections from unusual locations.

  • ✗

    Azure Activity connector and a rule for resource deletion

    Why it's wrong here

    The Azure Activity connector captures control-plane operations through Azure Resource Manager, such as creating, deleting, or scaling a database, and it records the actor who performed the management action. A connection to the database from an odd IP is a data-plane event that is not logged in the Activity Log, because the Activity Log does not include SQL connection attempts, queries, or failed logins. Therefore, a rule monitoring resource deletion would never see the geo-location of a database connection, making it an inappropriate detection strategy.

About these practice questions

Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.