A DBA believes enabling Microsoft Defender for SQL will encrypt the water-quality database at rest. What is the plan actually for?
Select an answer to reveal the explanation.
Short Explanation
Defender for SQL watches for shady queries and weak configs—it does not wrap the database in TDE. Encryption stays Domain 3; this plan is threat detection and vulnerability assessment.
Full Explanation
Microsoft Defender for SQL (within Defender for Databases) provides threat detection and vulnerability assessment for the SQL estate. Transparent Data Encryption and Always Encrypted remain Domain 3 data-plane controls and are not enabled by turning on the Defender for SQL plan. Confusing the plan with encryption, Storage malware scanning, or disabling auditing misunderstands its purpose.