Courseiva
mediumMatching

SC-200 Practice Question: Match each Microsoft Defender for Cloud security…

Match each Microsoft Defender for Cloud security alert to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Anomalous process run on a VM

Multiple failed login attempts from an IP

Antimalware scan found a threat

Download of a suspicious file from an external source

Unusual outbound data transfer detected

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

SQL Injection: Detects attempts to inject malicious SQL code into application queries.

Correct matches: SQL Injection detects SQL code injection, Brute Force detects multiple failed logins, Malware Alert detects known malware. Common confusions include swapping definitions between these alerts.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    SQL Injection: Detects attempts to inject malicious SQL code into application queries.

    Why this is correct

    This is the correct mapping because SQL injection is an application-layer attack that manipulates unsanitized user input to alter the behavior of database queries, such as appending ' OR '1'='1' to bypass authentication. Defender for Cloud detects these attempts by analyzing SQL statement anomalies and known injection patterns across Azure SQL, Log Analytics, and other data services. The alert specifically fires when malicious code is inserted into a query string, not when an attacker repeatedly submits passwords.

  • ✓

    Brute Force: Detects multiple failed login attempts from a single source.

    Why this is correct

    A brute force alert correctly corresponds to multiple failed login attempts from a single source because this indicates a systematic authentication attack using password guessing, credential stuffing, or password spraying. Defender for Cloud's detection logic correlates sign-in failures by originating IP address, account, and time window to distinguish automated guessing from legitimate user errors. It is not about data access via input manipulation, but rather about compromising credentials themselves.

  • ✓

    Malware Alert: Detects known malicious software on a protected resource.

    Why this is correct

    This is correct because a malware alert in Defender for Cloud is triggered when known malicious software, such as a virus, Trojan, or ransomware, is detected on a protected workload like a VM or storage account. Detection relies on signature matching, behavior-based monitoring, and file reputation gathered from Microsoft threat intelligence. The alert indicates the presence of the malicious binary itself, not the method by which it was delivered or an attempt to exploit an application.

  • ✗

    SQL Injection: Detects multiple failed login attempts from a single source.

    Why it's wrong here

    This statement is incorrect because it conflates SQL injection with brute force; repeated failed login attempts from a single source are the signature of an authentication attack, not an attempt to inject malicious SQL code. SQL injection instead involves crafting input that gets executed as part of a database query, such as using a single quote to break out of a string literal. In Defender for Cloud, a brute force alert is raised independently based on authentication logs, whereas a SQL injection alert analyzes query text and execution anomalies.

  • ✗

    Malware Alert: Detects attempts to inject malicious SQL code.

    Why it's wrong here

    This is incorrect because malware alerts are based on the presence of known malicious files or code artifacts, not on the process of injecting SQL into application queries. A SQL injection attempt is a web application attack technique that may eventually deliver a payload, but the attempt itself is not malware; for example, a malicious query string would not be flagged by antivirus signatures. Defender for Cloud classifies SQL injection as an application-layer vulnerability exploitation alert, separate from malware detection which focuses on file hashes, behavior, and reputation.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.