Courseiva
mediumMultiple Choice

SC-200 Practice Question: A security team wants to enable advanced threat…

A security team wants to enable advanced threat detection for all Azure SQL databases across multiple subscriptions. They want to receive alerts for SQL injection attempts and anomalous activities. Which action should they take in Microsoft Defender for Cloud?

⚠ Common exam trap

Test-takers frequently confuse the need for per-server configuration (Option C) with the centralized subscription-level enablement, or they mistakenly think that server-level security controls like firewalls (Option D) or server-specific plans (Option A) can provide the same threat detection capabilities.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable the Microsoft Defender for SQL plan at the subscription level.

Microsoft Defender for SQL provides advanced threat detection for Azure SQL databases, including alerts for SQL injection attempts and anomalous activities. Enabling the plan at the subscription level automatically protects all existing and future SQL databases within that subscription, ensuring centralized management and compliance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable the Microsoft Defender for Servers plan on each subscription.

    Why it's wrong here

    Microsoft Defender for Servers is designed for infrastructure-as-a-service (IaaS) workloads, providing endpoint detection and response (EDR), file integrity monitoring, and just-in-time VM access. It does not apply to platform-as-a-service (PaaS) resources like Azure SQL Database, so enabling it on a subscription will not produce SQL-specific threat alerts such as SQL injection or anomalous access detection. Your SQL databases remain unprotected at the database layer if only this plan is enabled.

  • ✓

    Enable the Microsoft Defender for SQL plan at the subscription level.

    Why this is correct

    Microsoft Defender for SQL is the correct security plan to enable at the subscription level, as it automatically protects all Azure SQL Database, Azure SQL Managed Instance, and Azure Synapse SQL pools within that subscription. It delivers advanced threat protection that continuously monitors database activity, detects SQL injection attempts, suspicious access patterns, and brute-force attacks, and provides actionable security alerts directly in Defender for Cloud. One subscription-level enablement applies the protection to every existing and future database, eliminating the need for per-server configuration.

  • ✗

    Configure SQL Auditing and Threat Detection on each SQL server individually.

    Why it's wrong here

    Manually configuring SQL Auditing and Threat Detection on each SQL server is a legacy, fragmented approach that does not offer the same level of protection as Defender for SQL. It requires you to individually enable auditing and set up alert rules on every server, creating an administrative overhead and a high risk of missing resources. Moreover, it does not include the advanced anomaly detection and vulnerability assessment capabilities that are built into Microsoft Defender for SQL.

  • ✗

    Create an Azure Policy to deploy Azure SQL Firewall rules.

    Why it's wrong here

    Deploying Azure SQL Firewall rules via Azure Policy addresses network layer access by controlling which source IP addresses can connect to your databases, but it does not perform any deep inspection of database queries or user behavior. Firewall rules cannot detect or alert on SQL injection, privilege escalation, or other database-level threats, so they are irrelevant to the requirement of advanced threat detection. Network controls like this should complement, not replace, a data-plane security solution such as Defender for SQL.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.