Courseiva
mediumMultiple ChoiceObjective-mapped

SC-200 Practice Question: A company has several Azure virtual machines…

A company has several Azure virtual machines running SQL Server (IaaS). The security team wants to enable Advanced Threat Protection for these SQL Server instances to detect threats like SQL injection. What should they do?

⚠ Common exam trap

A common mix-up: candidates confuse Azure Defender for Servers with Azure Defender for SQL, assuming server-level protection automatically covers SQL workloads, but SQL-specific threat detection requires the dedicated SQL Defender plan and the IaaS Agent extension.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Deploy the SQL Server IaaS Agent extension on each VM and enable Azure Defender for SQL in Microsoft Defender for Cloud.

To enable Advanced Threat Protection for SQL Server IaaS, you must deploy the SQL Server IaaS Agent extension on each VM, which allows the VM to register with the SQL IaaS platform. Then, you enable Azure Defender for SQL in Microsoft Defender for Cloud, which provides threat detection for SQL injection and other anomalous activities. This combination ensures the SQL Server instances are monitored by Defender for Cloud's SQL-specific protections.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Deploy the SQL Server IaaS Agent extension on each VM and enable Azure Defender for SQL in Microsoft Defender for Cloud.

    Why this is correct

    Correct. The SQL IaaS Agent extension registers the VM with the SQL resource provider. After that, enabling Azure Defender for SQL (under Defender for Cloud plans) provides Advanced Threat Protection and vulnerability assessment for the SQL Server instances.

  • Enable Azure Defender for Servers on the subscription; it automatically protects SQL Server workloads.

    Why it's wrong here

    Azure Defender for Servers (enabled at the subscription level) protects the host OS via features like just-in-time VM access, file integrity monitoring, and Microsoft Defender Antivirus endpoint detection, but it never receives SQL Server audit logs, parses T-SQL query patterns, or analyzes database schema vulnerabilities. As a result, it cannot detect SQL injection attacks, anomalous database logins, or database-specific misconfigurations on your SQL Server IaaS VMs. The SQL IaaS Agent extension must first register each VM with the Microsoft SQL resource provider, and only then can Azure Defender for SQL be enabled to deliver the database-level threat detection and vulnerability assessment that these workloads actually require.

  • Enable Azure Defender for SQL on the Log Analytics workspace used by the VMs.

    Why it's wrong here

    Azure Defender for SQL is a Microsoft Defender for Cloud plan that must be enabled at the subscription level or directly on the SQL resource (such as a SQL VM registered with the SQL IaaS Agent extension) — it cannot be enabled on a Log Analytics workspace. The Log Analytics workspace is only the data-ingestion and storage destination for security events, alerts, and diagnostic logs that Defender for Cloud or Sentinel collect; a workspace is not a SQL resource and has no database-level telemetry of its own. Enabling the plan at the workspace scope would fail to register the SQL VMs with the SQL resource provider and would therefore leave them without any SQL-specific protections, so this option confuses the data-collection plane with the actual Defender plan enforcement scope.

  • Configure the Microsoft Sentinel SQL connector to ingest SQL audit logs.

    Why it's wrong here

    The SQL connector in Sentinel ingests audit logs for analysis but does not enable the built-in threat detection capabilities of Azure Defender for SQL. The two are separate: Defender generates alerts, Sentinel can ingest them.

About these practice questions

This SC-200 question is part of Courseiva's 209-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.