Courseiva

AZ-305 Practice Question: Design identity, governance, and monitoring solutions

Your organization uses Microsoft Sentinel for security monitoring. You need to create a rule that triggers an incident when a user from a specific IP address performs more than 10 failed sign-ins within an hour. Which rule type should you use?

⚠ Common exam trap

A common mix-up: candidates confuse scheduled query rules with anomaly detection rules, assuming any threshold-based alert is 'anomaly detection,' but anomaly detection requires baseline learning and cannot enforce a static numeric threshold like 10.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Scheduled query rule

A scheduled query rule is the correct choice because it allows you to define a custom KQL query that counts failed sign-in events from a specific IP address over a 1-hour window and triggers an incident when the count exceeds 10. This rule type is designed for user-defined detection logic based on log data, such as SigninLogs, and supports aggregation and threshold-based alerting.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Microsoft Security rule

    Why it's wrong here

    A Microsoft Security rule in Sentinel is an ingestion-oriented analytics rule that imports and synchronizes pre-existing alerts from Microsoft security products such as Microsoft Defender for Cloud or Microsoft 365 Defender. It does not run a KQL query against raw stored logs, so it cannot aggregate Windows event data and evaluate a custom numeric threshold such as 'more than five failed logins within ten minutes.' Because it relies on the source service to generate alerts, it cannot be configured to detect an arbitrary threshold condition on log data, making it incorrect for this scenario.

  • ✓

    Scheduled query rule

    Why this is correct

    A scheduled query rule is the correct choice because it periodically executes a KQL query over a defined lookback window and evaluates the results against an alert condition. You can aggregate events with operators such as 'summarize count() by User, bin(TimeGenerated, 5m)' and design the query to return rows only when that aggregated count exceeds the desired threshold, such as five failed logins. The rule's configurable run frequency, lookback period, and alert settings make it the standard Sentinel mechanism for deterministic event-count threshold detection.

  • ✗

    Anomaly detection rule

    Why it's wrong here

    Anomaly detection rules rely on machine learning models that establish a dynamic baseline of expected behavior for each data source and alert when activity deviates statistically from that baseline. They do not support a directly configured, hard-coded threshold; the alert condition is derived from historical patterns and confidence percentiles. Since the organization in this question needs a simple, fixed threshold on an event count rather than a baseline-relative anomaly, an anomaly detection rule is the wrong choice because it would be both inaccurate and overly complex for that requirement.

  • ✗

    Fusion rule

    Why it's wrong here

    Fusion rules use machine learning to correlate alerts and signals from multiple security products into a single high-fidelity incident, targeting multi-stage attack chains such as a user login followed by suspicious PowerShell execution. A Fusion rule cannot be authored around a single aggregation condition on one log source, nor can it be given a custom threshold that counts a finite batch of events. Its purpose is to merge diverse evidence across sources, not to monitor a specific KQL count result, so it cannot satisfy the organization's simple threshold-based alerting need.

About these practice questions

Courseiva writes every AZ-305 question from scratch — 795 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.