AZ-500 exam dumps

AZ-500 practice question 176 of 273

Microsoft Azure Security Technologies. Associate level, Microsoft. Free question with the correct answer and a full explanation.

AZ-500 Question 176

Select 2

You are a security engineer for an e-commerce solution that uses a single Azure SQL Database. Your compliance requirements specify that you must track all SELECT and DML operations on the database and store the audit logs for 90 days in Azure Storage. Which two steps must you perform to meet these requirements? (Choose two.)

  1. A

    Enable Azure SQL Auditing at the server or database level, ensuring SELECT and DML statements are included in Audit Action Types.

  2. B

    Configure the audit to store logs in an Azure Storage account with a 90-day retention period.

  3. C

    Deploy Azure Defender for SQL to automatically audit all database activities.

  4. D

    Create a firewall rule that only allows traffic from your corporate IP addresses.

Show answer and explanation

Correct answers: A, B

Explanation

To meet the requirement of tracking SELECT and DML operations and storing them for 90 days, you must explicitly enable Azure SQL Auditing and then configure the audit destination as an Azure Storage account with the required retention period. Azure Defender for SQL focuses on threat detection and vulnerability assessments rather than core audit policy settings, and firewall rules only control inbound connections. Refer to Microsoft Docs (https://learn.microsoft.com/azure/azure-sql/database/auditing-overview) for more details on enabling and configuring auditing for Azure SQL Database.

  • A. Correct.

    Correct. Enabling Azure SQL Auditing at the server or database level and specifying Audit Action Types (including SELECT and DML) ensures those operations are tracked.

  • B. Correct.

    Correct. Storing audit logs in an Azure Storage account and retaining them for 90 days fulfills the compliance requirement for long-term log storage.

  • C. Incorrect.

    Incorrect. Azure Defender for SQL provides threat detection and vulnerability assessments but does not itself configure or handle basic audit logging settings.

  • D. Incorrect.

    Incorrect. Creating a firewall rule restricts access but does not configure auditing or log storage.

Timed practice exam

Take a AZ-500 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam