hardMultiple Choice
SC-200 Practice Question: A security analyst uses Microsoft Defender for…
A security analyst uses Microsoft Defender for Cloud to monitor Azure SQL Databases. The analyst wants to generate alerts for SQL injection attempts but only for databases that contain sensitive data (e.g., credit card numbers). What is the most efficient way to configure alerting to focus on these databases?
⚠ Common exam trap
Candidates may assume ATP can be scoped to specific databases or labels, but ATP is server-wide and does not integrate with Data Discovery & Classification labels. A Sentinel custom rule provides the required granularity.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable a custom alert rule in Microsoft Sentinel that queries Azure SQL audit logs and filters based on database classification tags.
The correct approach is to use an Azure Sentinel custom alert rule that queries Azure SQL audit logs and filters based on database classification tags. This ensures alerts are generated only for databases with sensitive data. Advanced Threat Protection (ATP) does not support filtering by classification labels and is enabled at the server level, making options B and C invalid.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enable a custom alert rule in Microsoft Sentinel that queries Azure SQL audit logs and filters based on database classification tags.
Why this is correct
A Microsoft Sentinel custom rule that queries Azure SQL audit logs would require shipping all SQL audit telemetry to the Log Analytics workspace, writing and maintaining KQL logic, and mapping data classification tags, which are stored as database metadata rather than as fields within individual audit log records. This approach is operationally heavy, adds detection latency, and fails to leverage the built-in machine-learning anomaly detection in Defender for Cloud's Advanced Threat Protection, so it is not the recommended or efficient solution.
- ✗
Use Data Discovery & Classification in Azure SQL to label sensitive columns, then configure Advanced Threat Protection to alert only when a SQL injection event is detected against a database with those labels.
Why it's wrong here
Data Discovery & Classification in Azure SQL labels columns containing sensitive data, such as credit card or health records, and this sensitivity context is recognized by Defender for Cloud. By combining those labels with Advanced Threat Protection, SQL injection detection can be focused on databases that actually hold sensitive information, which minimizes noise from less critical databases and aligns the alert pipeline with data classification as the authoritative filter.
- ✗
Disable Advanced Threat Protection for all databases except those that contain sensitive data by manually enabling ATP per database.
Why it's wrong here
Manually disabling Advanced Threat Protection on every non-sensitive database requires one-by-one configuration and continuous supervision; any new database that is provisioned or any reclassification of existing data will not be automatically reflected, leaving either unprotected sensitive data or unnecessary ATP on unimportant systems. This approach is neither scalable nor self-maintaining, unlike centrally managed Defender for Cloud policies that can enforce ATP based on classification metadata.
- ✗
Create a workflow automation in Defender for Cloud that filters SQL injection alerts based on database name.
Why it's wrong here
Workflow automation in Defender for Cloud operates as a response trigger that reacts to alerts after they are already generated, so it cannot suppress or filter incoming SQL injection alerts based on database name at the prevention layer. Relying on database name is also brittle because a database's name does not indicate its sensitivity; using the classification labels is the appropriate attribute for targeting alerts.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.