AZ-500 Manage identity and access Practice Question
A security team has a list of known malicious IP addresses from an external threat intelligence feed in CSV format. They want to import this list into Microsoft Sentinel and use it in analytics rules to detect incoming attacks. Which feature should they use?
⚠ Common exam trap
Many candidates confuse Watchlists with Threat intelligence indicators, as both can handle IP lists, but TI indicators require a formal TI platform integration and STIX/TAXII protocols, whereas Watchlists are the correct choice for simple CSV imports without additional infrastructure.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Watchlists
Watchlists in Microsoft Sentinel allow you to import external data sources, such as CSV files containing known malicious IP addresses, and use them directly in analytics rules for detection. This feature is designed for lightweight, custom threat intelligence that doesn't require the full threat intelligence indicator (TI) lifecycle, making it ideal for ad-hoc lists from CSV feeds.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Watchlists
Why this is correct
Watchlists are the correct choice because Microsoft Sentinel's Watchlists feature allows you to import CSV files directly and store them in your workspace, making them queryable via the _GetWatchlist function. You can create a watchlist from a CSV containing your known malicious IP addresses, then reference it in analytics rules with KQL to match against incoming events, enabling custom threat intelligence without a formal TI feed.
- ✗
Threat intelligence indicators
Why it's wrong here
Threat intelligence indicators are incorrect because they require a structured format such as STIX/TAXII and are ingested through Threat Intelligence platform connectors or the Threat Intelligence data connectors. Manually uploading a CSV list of IPs is not the intended workflow for TI indicators—those are for automated, standardized feeds, and attempting to use them for a one-off manual list would not adapt well.
- ✗
Bookmark
Why it's wrong here
Bookmarks are incorrect because in Microsoft Sentinel, a bookmark is a saved hunting query or specific set of search results used to capture interesting events for later investigation and correlation. Bookmarks do not import external data or serve as a static lookup source, so they cannot be used to match incoming events against your known malicious IP list.
- ✗
User and Entity Behavior Analytics (UEBA)
Why it's wrong here
UEBA is incorrect because User and Entity Behavior Analytics in Microsoft Sentinel uses machine learning to profile normal behavior for users, hosts, and other entities, then detects anomalies that deviate from those baselines. UEBA is not designed to ingest and statically match a precompiled list of hostile IP addresses; it focuses on behavioral detections rather than deterministic indicator matching.
Go deeper
Related to this question
About these practice questions
This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.