nerdexam
Microsoft

AZ-500 · Question #491

You have an Azure subscription that contains an Azure SQL server named SQL1. SQL1 contains an Azure SQL database named DB1. You need to use Microsoft Defender for Cloud to complete a vulnerability…

The correct answer is D. Enable the Microsoft Defender for SQL plan. To perform a vulnerability assessment for an Azure SQL database using Microsoft Defender for Cloud, you must first enable the specific Microsoft Defender for SQL plan.

Submitted by hassan_iq· Mar 6, 2026Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel

Question

You have an Azure subscription that contains an Azure SQL server named SQL1. SQL1 contains an Azure SQL database named DB1. You need to use Microsoft Defender for Cloud to complete a vulnerability assessment for DB1. What should you do first?

Options

  • AFrom Advanced Threat Protection types, select SQL injection vulnerability.
  • BConfigure the Send scan report to setting.
  • CSet Periodic recurring scans to ON.
  • DEnable the Microsoft Defender for SQL plan.

How the community answered

(32 responses)
  • A
    3% (1)
  • C
    6% (2)
  • D
    91% (29)

Why each option

To perform a vulnerability assessment for an Azure SQL database using Microsoft Defender for Cloud, you must first enable the specific Microsoft Defender for SQL plan.

AFrom Advanced Threat Protection types, select SQL injection vulnerability.

Selecting SQL injection vulnerability as an Advanced Threat Protection type is a specific configuration for a different security feature within Defender for SQL, not the initial step for enabling vulnerability assessments.

BConfigure the Send scan report to setting.

Configuring the 'Send scan report to' setting is a post-enablement configuration option for how vulnerability assessment reports are distributed, not the initial enabling step.

CSet Periodic recurring scans to ON.

Setting 'Periodic recurring scans' to ON is a configuration option for automating vulnerability assessments once the Defender for SQL plan is enabled, not the initial enabling step.

DEnable the Microsoft Defender for SQL plan.Correct

Enabling the Microsoft Defender for SQL plan is the prerequisite for accessing and utilizing its security features, including the vulnerability assessment capabilities for Azure SQL databases.

Concept tested: Enabling Microsoft Defender for SQL for vulnerability assessment

Source: https://learn.microsoft.com/en-us/azure/defender-for-cloud/defender-for-sql-introduction

Community Discussion

No community discussion yet for this question.

Full AZ-500 Practice