Courseiva
Manage identity and access →mediumMultiple Choice

AZ-500 Manage identity and access Practice Question

A security analyst is using Microsoft Sentinel to detect multi-stage attacks. They want to create an analytics rule that correlates a user sign-in from an unusual location with a subsequent data exfiltration attempt from Azure Blob Storage within one hour. Which type of analytics rule should they use?

⚠ Common exam trap

Many exam-takers confuse Fusion rules (which also correlate events) with scheduled queries, but Fusion rules are limited to pre-built correlations from Microsoft security products, whereas scheduled queries allow custom KQL logic across any data source.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Scheduled query rule with entity mapping.

A scheduled query rule with entity mapping is correct because it allows the security analyst to write a KQL query that correlates two distinct events—a sign-in from an unusual location and a subsequent data exfiltration from Azure Blob Storage—within a defined time window (one hour). Entity mapping enables the rule to link these events by common entities (e.g., user account or IP address), which is essential for detecting multi-stage attacks. This rule type runs on a schedule, making it ideal for time-bound correlation queries.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Scheduled query rule with entity mapping.

    Why this is correct

    Scheduled query rules are the only listed Sentinel analytics rule type that execute custom KQL directly against Log Analytics workspace tables, so an analyst can write a query that joins storage logs, sign-in logs, and other data sources within a defined lookback window to detect multi-event sequences. Entity mapping is what turns query result rows into normalized alert entities—Account, Host, IP, URL—so Sentinel can enrich the incident, correlate related alerts, and pass machine-readable context to playbooks and investigations. This makes it the correct choice when the SOC needs custom detection logic that matches a specific attack pattern rather than relying on a built-in source alert.

  • ✗

    Fusion rule.

    Why it's wrong here

    Fusion rules rely on machine-learning correlation over alerts already generated by Microsoft security products such as Microsoft 365 Defender, Defender for Cloud, and Microsoft Entra ID Protection; they do not query raw workspace data or custom log sources like storage diagnostics. An analyst cannot configure a Fusion rule with custom KQL, entity mappings, or arbitrary table inputs—instead, Fusion automatically recognizes multi-stage attack narratives from alert metadata such as kill-chain phases, severity, timestamps, and shared entities. Because the detection scenario requires querying custom storage logs directly, Fusion is not applicable.

  • ✗

    Microsoft Security incident rule.

    Why it's wrong here

    A Microsoft Security incident analytics rule is essentially an incident ingestion pipeline: it subscribes to incidents already produced by upstream Microsoft services and copies them into Sentinel based on filters like service, severity, and incident name, not on a KQL query. It performs no local correlation or custom log analysis because the detection logic lives entirely in the originating Microsoft security product, and it cannot inspect custom tables such as storage account logs or Sysmon for event sequences. This rule type is therefore irrelevant when the analyst needs to author custom multi-event detection logic in Sentinel.

  • ✗

    Anomaly rule.

    Why it's wrong here

    Anomaly analytics rules use built-in machine-learning models—such as anomalous sign-in behavior, unusual resource creation, or abnormal data extraction—to learn a statistical baseline from historical Sentinel data and then generate alerts when new activity deviates beyond an expected threshold. They are not query-driven, do not accept custom KQL, and cannot be pointed at arbitrary log sources like storage audit logs to find a specific sequence of correlated events; they also lack the explicit entity mapping used to normalize deterministic pattern matches. For a known multi-event detection scenario, an anomaly rule would only indicate that something is statistically unusual rather than confirm the analyst's exact correlation logic.

Quick reference

Azure Blob Storage Tier Comparison

TierStorage CostRetrieval CostLatencyUse Case
HotHighestLowestImmediateActive data, frequent reads
CoolLowerHigherImmediateData accessed < once / month
ColdLower stillHigherImmediateData accessed < once / quarter
ArchiveLowestHighest + rehydration delayHoursLong-term compliance retention

About these practice questions

This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.