SC-100 · Question #344
You have an Azure subscription. You have an on-premises datacenter that contains Microsoft SQL Server instances. Each instance contains multiple databases. You have a Microsoft 365 subscription. You…
The correct answer is C. Microsoft Defender for Cloud. Microsoft Defender for Cloud is the prerequisite for scanning on-premises SQL Server instances for security vulnerabilities. It includes Microsoft Defender for SQL, a sub-plan that performs vulnerability assessments on SQL Server databases - including those running on-premises…
Question
You have an Azure subscription. You have an on-premises datacenter that contains Microsoft SQL Server instances. Each instance contains multiple databases. You have a Microsoft 365 subscription. You plan to implement a solution to scan the databases for vulnerabilities that compromise data security. You need to recommend what to configure before the databases can be scanned. What should you recommend?
Options
- AMicrosoft Purview data loss prevention (DLP)
- BMicrosoft Purview data governance
- CMicrosoft Defender for Cloud
- DMicrosoft Defender Vulnerability Management
How the community answered
(43 responses)- A2% (1)
- B12% (5)
- C81% (35)
- D5% (2)
Explanation
Microsoft Defender for Cloud is the prerequisite for scanning on-premises SQL Server instances for security vulnerabilities. It includes Microsoft Defender for SQL, a sub-plan that performs vulnerability assessments on SQL Server databases - including those running on-premises. To enable this for on-premises servers, the SQL instances must first be onboarded to Azure Arc (making them Arc-enabled machines), and then Defender for SQL must be enabled within Defender for Cloud. The question asks what to configure 'before' scanning can occur, and Defender for Cloud is the platform-level service that must be provisioned and configured to unlock this capability. A (Purview DLP) prevents sensitive data from being exfiltrated but does not scan for SQL vulnerabilities. B (Purview data governance) catalogs and classifies data assets; it does not perform vulnerability scanning. D (Defender Vulnerability Management) focuses on OS-level and application vulnerabilities on endpoints; it is not the correct service for SQL Server database vulnerability assessments, which fall under Defender for Cloud's Defender for SQL plan.
Topics
Community Discussion
No community discussion yet for this question.