Microsoft Certified: Azure Security Engineer AssociateManage security operationsMedium

A security engineer is configuring Azure Security Center (now Microsoft Defender for Cloud) to protect SQL databases. They want to ensure that all SQL servers are continuously monitored for suspicious database activities, such as SQL injection attempts or unusual access patterns. Which specific Defender for Cloud plan should be enabled to provide this advanced threat protection for SQL databases?

  1. AMicrosoft Defender for SQL
  2. BMicrosoft Defender for Servers
  3. CMicrosoft Defender for Storage
  4. DMicrosoft Defender for App Service
Show answer & explanation

Correct answer: A. Microsoft Defender for SQL

Microsoft Defender for SQL is a specific plan within Microsoft Defender for Cloud that provides a comprehensive set of security capabilities for SQL databases, including vulnerability assessment, advanced threat protection for SQL injection, unusual access, and other suspicious activities.

Why the other options are wrong

  • B. Defender for Servers protects virtual machines and physical servers, not specifically SQL database activities.
  • C. Defender for Storage provides threat protection for Azure Storage accounts, not SQL databases.
  • D. Defender for App Service protects Azure App Service plans, not SQL databases.

Microsoft Defender for SQL

Microsoft Defender for SQL is a security offering within Microsoft Defender for Cloud that protects Azure SQL Database, Azure SQL Managed Instance, and SQL Server on Azure Virtual Machines. It includes vulnerability assessment and advanced threat protection capabilities.

  • Protects Azure SQL Database, Managed Instance, and SQL on VMs.
  • Includes vulnerability assessment.
  • Detects SQL injection, unusual access, and other threats.
  • Provides actionable security alerts.

Memory trick: Each Defender plan protects a specific cloud treasure.

More Manage security operations questions