Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.

Unlimited Access

Get Unlimited Contributor Access to the all ExamTopics Exams!
Take advantage of PDF Files for 1000+ Exams along with community discussions and pass IT Certification Exams Easily.

Exam AZ-500 topic 1 question 19 discussion

Actual exam question from Microsoft's AZ-500
Question #: 19
Topic #: 1
[All AZ-500 Questions]

You have been tasked with enabling Advanced Threat Protection for an Azure SQL Database server.
Advanced Threat Protection must be configured to identify all types of threat detection.
Which of the following will happen if when a faulty SQL statement is generate in the database by an application?

  • A. A Potential SQL injection alert is triggered.
  • B. A Vulnerability to SQL injection alert is triggered.
  • C. An Access from a potentially harmful application alert is triggered.
  • D. A Brute force SQL credentials alert is triggered.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️
Reference:
https://docs.microsoft.com/en-us/azure/sql-database/sql-database-threat-detection-overview

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Rume
Highly Voted 2 years, 10 months ago
A possible vulnerability to SQL Injection (SQL.VM_VulnerabilityToSqlInjection SQL.DB_VulnerabilityToSqlInjection SQL.MI_VulnerabilityToSqlInjection SQL.DW_VulnerabilityToSqlInjection) An application has generated a faulty SQL statement in the database. This can indicate a possible vulnerability to SQL injection attacks. There are two possible reasons for a faulty statement. A defect in application code might have constructed the faulty SQL statement. Or, application code or stored procedures didn't sanitize user input when constructing the faulty SQL statement, which can be exploited for SQL injection. ) https://docs.microsoft.com/en-us/azure/security-center/alerts-reference#alerts-sql-db-and-warehouse
upvoted 47 times
MeisAdriano
7 months ago
I agree: possibile
upvoted 1 times
...
...
NarenderSingh
Highly Voted 2 years, 5 months ago
Selected Answer: B
correct
upvoted 6 times
...
Drummer
Most Recent 2 days, 3 hours ago
A Potential SQL injection alert is triggered. This alert is specifically mentioned as being triggered when an application generates a faulty SQL statement in the database. Advanced Threat Protection can identify potential SQL injection attempts and trigger security alerts upon detection of anomalous database activities. This option is the most appropriate because Advanced Threat Protection is designed to detect various types of threats, including SQL injection attacks. When a potentially harmful SQL statement is detected, it would likely trigger a SQL injection alert as it represents a potential vulnerability that could be exploited by attackers. https://learn.microsoft.com/en-us/azure/azure-sql/database/threat-detection-configure?view=azuresql https://learn.microsoft.com/en-us/azure/azure-sql/database/threat-detection-overview?view=azuresql
upvoted 1 times
...
Pamban
2 weeks, 2 days ago
Selected Answer: A
Potential SQL injection attacks - including vulnerabilities detected when applications generate a faulty SQL statement in the database https://learn.microsoft.com/en-us/azure/defender-for-cloud/defender-for-sql-introduction
upvoted 1 times
...
Mazhar1993
3 weeks, 3 days ago
The correct option is A Vulnerability to SQL injection alert is triggered: This aligns with the scenario where a faulty SQL statement suggests a possible vulnerability to SQL injection attacks due to improper user input sanitization. A Potential SQL injection alert is not triggered because the context describes a faulty SQL statement generated by an application, indicating a vulnerability rather than an actual SQL injection attempt. An Access from a potentially harmful application alert is not triggered as the context focuses on detecting vulnerabilities related to SQL injection rather than the origin or access pattern of the application. A Brute force SQL credentials alert is not triggered since the context does not indicate any brute force attack or credential-based intrusion attempt. https://learn.microsoft.com/en-us/azure/defender-for-cloud/alerts-reference#alerts-sql-db-and-warehouse
upvoted 1 times
...
orionduo
1 month, 2 weeks ago
Selected Answer: B
A possible vulnerability to SQL Injection (SQL.DB_VulnerabilityToSqlInjection SQL.VM_VulnerabilityToSqlInjection SQL.MI_VulnerabilityToSqlInjection SQL.DW_VulnerabilityToSqlInjection Synapse.SQLPool_VulnerabilityToSqlInjection) Description: An application has generated a faulty SQL statement in the database. This can indicate a possible vulnerability to SQL injection attacks. There are two possible reasons for a faulty statement. A defect in application code might have constructed the faulty SQL statement. Or, application code or stored procedures didn't sanitize user input when constructing the faulty SQL statement, which can be exploited for SQL injection.
upvoted 1 times
...
aks_exam
4 months, 1 week ago
Selected Answer: A
The answer is A. "A defect in application code might have constructed the faulty SQL statement. Or, application code or stored procedures didn't sanitize user input when constructing the faulty SQL statement, which can be exploited for SQL injection." https://learn.microsoft.com/en-us/azure/defender-for-cloud/alerts-reference#alerts-sql-db-and-warehouse
upvoted 1 times
...
yonie
4 months, 3 weeks ago
Selected Answer: B
Answer is B: A possible vulnerability to SQL Injection Alerts for SQL Database https://learn.microsoft.com/en-us/azure/defender-for-cloud/alerts-reference#alerts-sql-db-and-warehouse
upvoted 1 times
...
MathiasC
5 months, 4 weeks ago
Selected Answer: A
possible = potential
upvoted 1 times
...
wardy1983
6 months ago
Answer: B Explanation: vulnerability to SQL Injection (SQL.VM_VulnerabilityToSqlInjection SQL.DB_VulnerabilityToSqlInjection SQL.MI_VulnerabilityToSqlInjection SQL.DW_VulnerabilityToSqlInjection) An application has generated a faulty SQL statement in the database. This can indicate a possible vulnerability to SQL injection attacks. There are two possible reasons for a faulty statement. A defect in application code might have constructed the faulty SQL statement. Or, application code or stored procedures didn't sanitize user input when constructing the faulty SQL statement, which can be exploited for SQL injection. ) Reference: https://docs.microsoft.com/en-us/azure/sql-database/sql-database-threat-detection-overview
upvoted 1 times
...
MeisAdriano
7 months ago
Selected Answer: A
A. A Potential SQL injection alert is triggered. Most Voted A possible vulnerability to SQL Injection https://docs.microsoft.com/en-us/azure/security-center/alerts-reference#alerts-sql-db-and-warehouse
upvoted 2 times
...
BigShot0
7 months, 4 weeks ago
Selected Answer: A
Image #2 in this article lists the description as "Potential SQL Injection" https://learn.microsoft.com/en-us/azure/azure-sql/database/threat-detection-overview?view=azuresql
upvoted 1 times
...
Bonesurfer
8 months, 1 week ago
1. Potential is a technical synonym for possible 2. B states "A vulnerability for SQL Injection" and not "A possible Vulnerability SQL Injection" That's the difference. I was able to verify it in my Labs, Conclusion = A
upvoted 1 times
...
AbdallaAM
8 months, 2 weeks ago
Selected Answer: B
AZ 500 Book: When you enable ADS, threat protection is available for SQL. Threat protection for Azure SQL Database detects anomalous activities that indicate unusual and potentially harmful attempts to access or exploit databases. For example, an alert that may be generated by this feature is the possible vulnerability to SQL Injection. This alert might indicate a possible vulnerability to SQL injection attacks. Usually there are two possible reasons for a faulty statement: a defect in application code might have constructed the faulty SQL statement, or the application code/stored procedures didn’t sanitize user input.
upvoted 4 times
...
killbots
8 months, 3 weeks ago
Selected Answer: B
Agree with B
upvoted 1 times
...
ESAJRR
10 months, 1 week ago
Selected Answer: B
B. A Vulnerability to SQL injection alert is triggered.
upvoted 1 times
...
Dev1079
11 months, 2 weeks ago
Selected Answer: B
https://learn.microsoft.com/en-us/azure/defender-for-cloud/alerts-reference#alerts-sql-db-and-warehouse
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...