Azure Defender for SQL is enabled on SQL1 with all threat detection types turned on. Which of the following actions will Defender for SQL flag as a threat?
Choose an answer
Tap an option to check your answer.
Correct answer: A user attempts to sign in as SELECT * FROM table1..
Why this is the answer
Azure Defender for SQL detects anomalous activities indicating potential threats to your database. Attempting to sign in with "SELECT FROM table1" is a classic example of SQL injection, where an attacker tries to manipulate input fields to execute unauthorized SQL commands. Defender for SQL is designed to identify such malicious patterns, flagging it as a potential threat. Updating more than 50% of records or deleting more than 100 records, while potentially unusual, are legitimate database operations that, without other suspicious indicators, are not inherently malicious and would not typically trigger a Defender for SQL alert. Adding a user to the dbowner role is a privileged but standard administrative action, not a threat detection event.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed