mediumMultiple Choice
SC-200 Practice Question: A company uses Microsoft Defender for Cloud to…
A company uses Microsoft Defender for Cloud to protect Azure resources. They have an Azure SQL Database containing sensitive customer data. The security team wants to be alerted if a user attempts to perform SQL injection attacks against the database. Which Defender for Cloud plan must be enabled to receive SQL injection alerts?
⚠ Common exam trap
A common mix-up: candidates confuse Defender for App Service with protecting the database, but App Service only protects the web application layer, not the SQL database itself, so SQL injection alerts require Defender for SQL.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Defender for SQL
Defender for SQL is the correct plan because it specifically provides threat detection for Azure SQL Database, including alerts for SQL injection attempts. It analyzes database audit logs and anomalous query patterns to detect SQL injection attacks, which are a primary threat to sensitive data in SQL databases.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Defender for SQL
Why this is correct
Defender for SQL is the correct plan because it is the Defender for Cloud plan specifically designed to secure SQL databases, including Azure SQL Database. It provides threat detection for SQL injection attempts by monitoring database query patterns and comparing them against known attack signatures and anomalous activity. This plan also surfaces recommendations like vulnerability assessment findings and configuration weaknesses, making it the direct source for SQL injection alerting against PaaS SQL databases.
- ✗
Defender for Servers
Why it's wrong here
Defender for Servers is a Microsoft Defender for Cloud plan that protects your virtual machine infrastructure, covering operating system-level threats, endpoint detection, and file integrity monitoring. While it can help secure SQL Server running on a virtual machine, it does not natively monitor the data-plane operations of an Azure SQL Database, such as malformed queries or injection payloads. For PaaS Azure SQL Database, the responsible plan is Defender for SQL, not Defender for Servers.
- ✗
Defender for Storage
Why it's wrong here
Defender for Storage is a Defender for Cloud plan that secures Azure Blob Storage, Azure Files, and Azure Data Lake Storage, focusing on anomalies like unusual access patterns and malicious file uploads. SQL injection is a database-layer attack that targets the query engine of Azure SQL Database, not the storage layer where database files are persisted. Therefore, this plan would neither detect nor alert on SQL injection attempts, making it an incorrect selection.
- ✗
Defender for App Service
Why it's wrong here
Defender for App Service protects web applications running on Azure App Service by detecting attacks at the application layer, such as cross-site scripting and other web vulnerabilities. While SQL injection is often launched through a web application, the detection for Azure SQL Database's SQL injection comes from monitoring the database's query logs and execution plans—which is Defender for SQL's responsibility. Thus, Defender for App Service would catch the web traffic pattern but not classify it as a SQL injection alert against the backend database.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.