mediumMultiple ChoiceObjective-mapped
SC-200 Practice Question: A company uses Microsoft Defender for Cloud to…
A company uses Microsoft Defender for Cloud to protect their Azure resources. They have enabled the enhanced security features on a subscription that contains several Azure SQL databases. They want to be alerted if a user attempts to perform SQL injection attacks against these databases. Which Defender for Cloud plan specifically enables SQL injection detection alerts?
⚠ Common exam trap
Many exam-takers confuse Defender for App Service with SQL injection detection because App Service can host web applications that are vulnerable to SQL injection, but the question specifically asks for the plan that enables detection alerts against the SQL databases themselves, not the web layer.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Defender for SQL
Defender for SQL is the specific Microsoft Defender for Cloud plan that provides SQL-specific threat detection, including alerts for SQL injection attacks. This plan monitors SQL databases for anomalous activities such as SQL injection attempts, brute-force attacks, and unusual access patterns by analyzing query logs and audit records. Enabling Defender for SQL on the subscription activates these detection capabilities for Azure SQL databases, making it the correct choice for the scenario.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Defender for Servers
Why it's wrong here
Defender for Servers is a plan that secures Linux and Windows machines, whether in Azure or on-premises, with endpoint detection and response, file integrity monitoring, and vulnerability management. However, it does not ingest SQL database audit logs or query-level telemetry, so it cannot generate the SQL injection attempt alerts the company needs. The SQL-specific threat intelligence and alert logic reside exclusively in Defender for SQL.
- ✓
Defender for SQL
Why this is correct
Defender for SQL is the dedicated plan that protects Azure SQL Database, SQL Managed Instance, and SQL on Azure VMs by surfacing database-level threats. It analyzes SQL audit logs and query activity to detect SQL injection attempts, anomalous access patterns, brute-force attacks, and other database-specific vulnerabilities. This plan also provides vulnerability assessment and data discovery/classification, making it the only option here that directly addresses the requirement for SQL security alerts.
- ✗
Defender for App Service
Why it's wrong here
Defender for App Service focuses on web applications running in Azure App Service, detecting threats such as web shells, suspicious code execution, and brute-force attempts against web endpoints. Its detection engine relies on App Service traffic and runtime signals, not on database transaction logs or SQL queries. Because the company's need is explicitly for SQL database protection, this plan would leave SQL databases without the required threat alerts.
- ✗
Defender for Storage
Why it's wrong here
Defender for Storage monitors Azure Storage accounts for anomalies like unusual access patterns, egress to unusual IPs, and malware uploaded to Blob containers. It works on storage telemetry and control-plane events, which cannot reveal SQL injection or database query anomalies. Therefore, deploying this plan would secure the storage layer only and fail to emit alerts for SQL database threats.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 209 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.