hardMultiple Choice
SC-200 Practice Question: A company has multiple Azure subscriptions…
A company has multiple Azure subscriptions managed by Microsoft Defender for Cloud with enhanced security features enabled. The security team wants to ensure that all Azure SQL Servers have Advanced Data Security (ADS) enabled, including Vulnerability Assessment. They decide to use Azure Policy to enforce this at scale. Which built-in policy initiative should they assign to achieve this?
⚠ Common exam trap
Watch out — candidates often confuse a single policy (like 'Enable Advanced Threat Protection for SQL servers') with a policy initiative that bundles multiple related policies, leading them to select option D instead of the broader Azure Security Benchmark initiative that covers both ADS and Vulnerability Assessment enforcement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Azure Security Benchmark
The Azure Security Benchmark initiative includes built-in policies to enforce Advanced Data Security (ADS) and Vulnerability Assessment on Azure SQL Servers. Assigning this initiative at scale ensures compliance with security best practices across all subscriptions, as it contains the specific policy effect to enable ADS and VA automatically.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable Azure Monitor for VMs
Why it's wrong here
Enable Azure Monitor for VMs is an Azure Policy initiative designed to onboard virtual machines to Azure Monitor by deploying the Log Analytics agent and the Dependency Agent, enabling VM insights for performance and network monitoring. It does not contain any policy definitions that enable Advanced Data Security, vulnerability assessment, or other SQL-specific security controls. For SQL server security hardening, you need an initiative that targets SQL resources, such as the Azure Security Benchmark, not a VM-centric monitoring initiative.
- ✓
Azure Security Benchmark
Why this is correct
Azure Security Benchmark is a comprehensive policy initiative (policy set definition) that bundles multiple built-in policy definitions representing security best practices and compliance controls across services, including SQL servers. Specifically, it includes policies such as 'Advanced Data Security on SQL servers should be enabled' and 'Vulnerability assessment on SQL servers should be enabled', which together establish a baseline for SQL security. Assigning this initiative to the Azure subscription allows Microsoft Defender for Cloud to evaluate, audit, and automatically deploy the required SQL security settings, making it the correct choice for meeting the stated requirement.
- ✗
Deploy Diagnostics Settings for SQL Databases
Why it's wrong here
Deploy Diagnostics Settings for SQL Databases is a single Azure Policy definition, not an initiative, and its effect focuses on streaming SQL database diagnostic logs and metrics to a chosen destination like Log Analytics, Event Hub, or storage. It does not enable any security features such as Advanced Data Security, vulnerability assessment, or threat detection on SQL servers. Even if combined with other policies, this alone is insufficient because it only addresses log collection, not the underlying SQL security hardening mandated by compliance standards.
- ✗
Enable Advanced Threat Protection for SQL servers
Why it's wrong here
Enable Advanced Threat Protection for SQL servers is precisely a single policy definition (or a policy effect) that enables the ATP feature for SQL, which provides threat detection capabilities. However, an initiative is a grouping of many policies that together deliver a broader compliance framework, such as Azure Security Benchmark, which includes not only ATP but also vulnerability assessment, data encryption, auditing, and other security controls. Choosing this option would only enforce one narrow control and would fail to satisfy the comprehensive SQL security posture required by the Azure Security Benchmark standard.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.