AZ-500 Manage identity and access Practice Question
A KQL query in Microsoft Sentinel detects impossible travel but returns many false positives from known VPN egress IP addresses. Which two changes would best reduce noise while preserving useful detections?
⚠ Common exam trap
A common mix-up: candidates confuse reducing alert frequency (Option D) with reducing false positives, or think disabling a data connector (Option B) is a valid noise-reduction technique, when in fact both actions cripple detection capability rather than refining it.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Join or filter against a watchlist of approved VPN egress IPs
Integrating a watchlist of known VPN egress IPs allows the KQL query to filter out these trusted IPs, reducing false positives from impossible travel detections. Option C is also correct because excluding events where the source IP is in an approved network list directly removes noise from legitimate VPN traffic, preserving detection of truly anomalous sign-ins. Both approaches leverage Sentinel's watchlist or allowlist capabilities to maintain detection fidelity while minimizing alert fatigue.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Join or filter against a watchlist of approved VPN egress IPs
Why this is correct
Joining SigninLogs against a Sentinel watchlist of approved VPN egress IPs lets the query remove or tag sign-ins originating from trusted corporate VPN ranges before the impossible-travel logic is applied. A watchlist is the maintainable, centrally managed artifact for this, and the KQL join (or lookup) against _GetWatchlist('VPN-Egress') is the canonical way to enrich or filter anomalies. This directly targets the false-positive source while preserving all other sign-in telemetry.
- ✗
Disable the SigninLogs connector for the tenant
Why it's wrong here
Disabling the SigninLogs connector would stop ingestion of Microsoft Entra ID sign-in events entirely, meaning Sentinel would have no data on which to run the impossible-travel query, let alone distinguish legitimate VPN egress from risky anonymous IPs. This is a destructive platform-level change rather than a scoped detection-tuning action, and it would suppress all sign-in detections, not just false positives. It fails the stated requirement because threat hunting and other SigninLogs-based analytics would also be lost.
- ✓
Exclude events where the source IP is in the approved network list
Why this is correct
Excluding events where the source IP appears in the approved network list is also a valid KQL-level mitigation because it applies the same allowlist concept as a watchlist directly in the query predicate, for example, `where source_ip !in (approved_ips)` or `where source_ip notin (dynamic([...]))`. Provided the approved network list is maintained accurately and includes the VPN egress ranges, this will eliminate false positives for those IPs while leaving the underlying detection intact. This is correct for the stated requirement, though a watchlist is usually preferred for easier updates without editing the query.
- ✗
Raise the query frequency from 1 hour to 24 hours
Why it's wrong here
Raising the query frequency from 1 hour to 24 hours changes the alerting cadence, not the detection logic, so impossible-travel alerts from approved VPN egress IPs would still be generated—just less often. It also introduces up to 24 hours of delay in alert generation, which can undermine incident response for a real impossible-travel event. This does not distinguish trusted from untrusted IPs and therefore does not address the false positive's root cause.
Go deeper
Related to this question
About these practice questions
This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.