Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the capabilities of Microsoft Security solutionsMedium
A company is migrating its on-premises SQL databases to Azure SQL Database. They need a solution that provides advanced threat detection capabilities for these databases, such as identifying unusual database access patterns, SQL injection attacks, and potential data exfiltration attempts. Which Azure security solution should they enable?
- AMicrosoft Defender for Cloud Apps
- BAzure Firewall
- CAzure SQL Database Advanced Threat Protection
- DAzure Network Security Groups
Show answer & explanationAnswer & explanation
Correct answer: C. Azure SQL Database Advanced Threat Protection
Azure SQL Database Advanced Threat Protection (part of Microsoft Defender for SQL) provides a layer of security that detects anomalous activities indicating unusual and potentially harmful attempts to access or exploit databases.
Why the other options are wrong
- A. Microsoft Defender for Cloud Apps focuses on protecting SaaS applications, not directly on Azure SQL Database threats.
- B. Azure Firewall provides network-level protection for virtual networks, not specific database threat detection.
- D. Azure Network Security Groups provide basic network traffic filtering, not advanced database threat detection.
Azure SQL Database Advanced Threat Protection
A security feature for Azure SQL Database that detects anomalous database activities indicating unusual and potentially harmful attempts to access or exploit databases.
- Detects SQL injection
- Identifies unusual access patterns
- Part of Microsoft Defender for SQL
Memory trick: SQL ATP protects your database with advanced threat detection.