AZ-500 exam dumps

AZ-500 practice question 177 of 273

Microsoft Azure Security Technologies. Associate level, Microsoft. Free question with the correct answer and a full explanation.

AZ-500 Question 177

Select 2

You are a security engineer for Contoso. Compliance requirements mandate that all newly created Azure SQL Databases must have auditing enabled to capture successful and failed logins, T-SQL statements, and administrative actions. You must retain the audit logs for at least 90 days in an existing Azure Blob Storage account, which already has lifecycle management rules for older data. Which two actions should you take to meet these auditing requirements?

  1. A

    Enable server-level auditing for your Azure SQL server to send audit logs to the existing Azure Blob Storage account, specifying a minimum retention period of 90 days.

  2. B

    Enable Azure Defender for SQL on your Azure SQL server, which automatically stores audit logs in a Log Analytics workspace.

  3. C

    Enable database-level auditing on each Azure SQL Database without referencing any server-level settings, storing logs in a default Event Hub.

  4. D

    Configure a lifecycle management rule on the Azure Blob Storage container to archive or delete audit logs older than 90 days.

  5. E

    Enable Transparent Data Encryption (TDE) on the Azure SQL Databases to fulfill the auditing requirement.

Show answer and explanation

Correct answers: A, D

Explanation

To implement Azure SQL Database auditing with a 90-day retention, you should configure a server-level auditing policy to send logs to Azure Blob Storage (any databases under that server will inherit those auditing settings), and use lifecycle management rules on the storage account to manage log retention beyond 90 days. Enabling Azure Defender for SQL provides threat detection capabilities but does not automatically configure auditing. Transparent Data Encryption (TDE) protects data at rest and is separate from the auditing process. For more details, refer to Microsoft documentation on 'Azure SQL Database Auditing' and 'Manage lifecycle policies in Azure Storage'.

  • A. Correct.

    Correct. Server-level auditing ensures consistent settings across all databases on the server. Directing logs to an Azure Blob Storage account is a standard practice, and you can specify a 90-day retention to meet compliance needs.

  • B. Incorrect.

    Incorrect. While Azure Defender for SQL (formerly Advanced Threat Protection) provides additional security features like threat detection, it does not replace or automatically configure auditing. You must explicitly enable and configure Azure SQL auditing to capture the required events.

  • C. Incorrect.

    Incorrect. Enabling database-level auditing individually might be more cumbersome and is unnecessary if a server-level policy is already set. Storing logs in Event Hub by default is not part of the standard auditing configuration; you'd need to configure that explicitly. It also doesn't integrate with the existing Blob Storage retention requirement.

  • D. Correct.

    Correct. Lifecycle management rules in Azure Blob Storage can automatically archive or delete logs older than 90 days. This approach meets the requirement to maintain at least 90 days of audit logs cost-effectively.

  • E. Incorrect.

    Incorrect. Transparent Data Encryption (TDE) encrypts data at rest within the database but does not fulfill the requirement of auditing successful/failed logins and T-SQL statements. TDE is a data protection measure, not an auditing measure.

Timed practice exam

Take a AZ-500 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam