You have an Azure subscription with several Azure SQL databases and an Azure Sentinel workspace. To create a saved query in the workspace that finds events reported by Azure Defender for SQL, where should you create the query?
Choose an answer
Tap an option to check your answer.
Correct answer: From the Azure Sentinel workspace, create a Kusto query language query..
Why this is the answer
The correct answer is to create a Kusto Query Language (KQL) query from the Azure Sentinel workspace. Azure Sentinel uses KQL for querying logs and security events. Azure Defender for SQL integrates with Azure Sentinel, sending security alerts and events to the Sentinel workspace. Therefore, to analyze these events, you must use KQL within Sentinel. Incorrect options: Running a PowerShell cmdlet (Get-AzOperationalInsightsWorkspace) via Azure CLI is for retrieving workspace information, not for creating queries. The Azure SQL Database query editor and SQL Server Management Studio (SSMS) are used for querying data within SQL databases using Transact-SQL (T-SQL). While Azure Defender for SQL protects these databases, the security events themselves are ingested into Azure Sentinel, which requires KQL, not T-SQL.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed