mediumMultiple Choice
SC-200 Practice Question: A security team enables Microsoft Defender for…
A security team enables Microsoft Defender for Cloud on an Azure subscription and wants to ensure that all Azure SQL databases have threat detection enabled. Which plan must be enabled to receive alerts for SQL injection attempts?
⚠ Common exam trap
Many exam-takers confuse Defender for Servers with general database protection, not realizing that SQL-specific threat detection requires the dedicated Defender for SQL plan, not the server-level plan.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Defender for SQL
Defender for SQL is the specific Microsoft Defender for Cloud plan that provides threat detection for Azure SQL databases, including alerts for SQL injection attacks. It monitors database activity for anomalous patterns, such as SQL injection attempts, and generates security alerts. Without this plan enabled, threat detection for SQL databases remains disabled, even if other Defender plans are active.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Defender for Servers
Why it's wrong here
Defender for Servers is a workload-protection plan focused on virtual machines and on-premises servers, delivering endpoint detection via Microsoft Defender for Endpoint, vulnerability assessment, and host-level intrusion alerts. Although a SQL Server instance may run on such a VM, this plan does not analyze database audit logs, query patterns, or SQL-specific attack indicators such as injection. SQL database security in Defender for Cloud belongs to the separate Defender for SQL plan, even when targeting SQL Server on a VM.
- ✓
Defender for SQL
Why this is correct
Microsoft Defender for SQL is the specialized plan that secures Azure SQL Database, Azure SQL Managed Instance, and SQL Server on Azure VMs/on-premises through Defender for Cloud. It combines advanced threat protection with SQL injection detection, anomalous access-pattern alerts, and vulnerability assessments at the database layer. This is the only plan among the choices that is designed to protect a SQL database and surface database-specific recommendations.
- ✗
Defender for Storage
Why it's wrong here
Defender for Storage is scoped to Azure Blob Storage, Azure Files, and Azure Data Lake Storage Gen2, providing threat detection for file and object workloads through anomaly detection and integrity monitoring. It does not integrate with or monitor SQL database engines, query activity, or database schemas, so any alerts it generates relate to storage access and content, not SQL injection or database exploits.
- ✗
Defender for Key Vault
Why it's wrong here
Defender for Key Vault uses cloud intelligence to monitor requests to Azure Key Vault, detecting suspicious patterns such as unusual access from known bad IPs, over-provisioning of secrets, or a vault being compromised. Its scope is entirely on the control and data plane of key vault objects, so it sees no database queries or SQL server traffic and cannot provide protection for SQL databases.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.