A company has enabled Microsoft Defender for Cloud on their subscription containing Azure SQL databases. They receive an alert about a potential SQL injection attack. The analyst wants to see the actual query that was executed. Where can the analyst find the query details associated with the alert?
The entity tab on a Microsoft Defender for Cloud alert details page provides a curated, contextual view of all affected resources and associated security entities. For SQL alerts, this includes the exact SQL query text that triggered the detection, along with related details such as the user account, source IP, and database. This is the designed interface to locate the flagged query, as it is directly tied to the alert's investigation workflow.
Why this answer
When Microsoft Defender for Cloud detects a SQL injection attack, the alert details include an 'Entities' tab that contains the actual SQL query that was executed. This tab provides the raw query text, which is essential for the analyst to understand the exact payload used in the attack and to assess the impact on the database.
Exam trap
The trap here is that candidates often confuse the Azure Activity Log (control-plane) with data-plane logs, or assume that threat detection logs are the primary source for query details, when in fact the alert's entity tab is the direct, curated source for the executed query.
How to eliminate wrong answers
Option B is wrong because SQL database's threat detection logs (e.g., Azure SQL Auditing or Advanced Threat Protection logs) may show query patterns but do not directly expose the specific query associated with a Defender for Cloud alert; the alert itself surfaces the query in its entities. Option C is wrong because the Azure Activity Log records control-plane operations (e.g., resource creation, policy changes) and does not capture data-plane events like SQL queries executed against a database. Option D is wrong because the alert's diagnostic data typically includes metadata such as severity, timestamp, and affected resources, but not the actual SQL query text; that is stored in the entities tab.