AZ-500 Practice Question: Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel
A security analyst needs to query Microsoft Sentinel logs to find all sign-in events from a specific IP address in the last 24 hours. Which query language should the analyst use?
⚠ Common exam trap
Many candidates confuse query languages used in other Microsoft services, such as T-SQL for databases or GraphQL for APIs, with the native language for Sentinel.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Kusto Query Language (KQL)
Microsoft Sentinel is built on Azure Monitor Log Analytics, which uses Kusto Query Language (KQL) for all log queries. KQL is optimized for fast filtering, sorting, and aggregation of large datasets. The analyst can write a KQL query against the SigninLogs table to find events from a specific IP within the last 24 hours, making it the correct choice.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
GraphQL
Why it's wrong here
GraphQL is a query language for APIs, commonly used with Microsoft Graph, but it is not used for querying Microsoft Sentinel logs. Microsoft Graph can retrieve some security data, but Sentinel logs are queried using KQL. GraphQL would not provide the ability to search sign-in events in Sentinel's Log Analytics workspace.
- ✗
Transact-SQL (T-SQL)
Why it's wrong here
T-SQL is used for querying Microsoft SQL Server and Azure SQL databases, not for querying Microsoft Sentinel logs. While both are query languages, T-SQL is not supported in Sentinel's Log Analytics workspace. The analyst would not be able to query sign-in events using T-SQL in this context.
- ✗
PowerShell
Why it's wrong here
PowerShell is a scripting language used for automation and management, not for directly querying Sentinel logs. While you can use PowerShell to call the Log Analytics API, it is not the native query language for Sentinel. The analyst would need to use KQL within the API call, making PowerShell an indirect method.
- ✓
Kusto Query Language (KQL)
Why this is correct
Microsoft Sentinel uses Kusto Query Language (KQL) for log queries and analytics. KQL is designed for querying large datasets in Azure Monitor and Log Analytics, and it supports filtering, aggregation, and time-based queries. The analyst can use KQL to search sign-in logs, such as SigninLogs, and filter by IP address and time range.
Go deeper
Related to this question
About these practice questions
This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.