AZ-500 Manage identity and access Practice Question
A Sentinel analyst needs to preserve investigation notes, related entities, and ownership while escalating a case to another analyst. Which object should be updated?
⚠ Common exam trap
Test-takers frequently confuse operational artifacts (watchlists, workbooks, connectors) with the incident object that actually holds case-specific metadata, leading them to select a static or non-persistent option instead of the dynamic incident record.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The Sentinel incident
The Sentinel incident object is the correct entity to update because it serves as the central container for investigation notes, related entities, and ownership assignments during case escalation. Updating the incident preserves the full investigation context—including comments, tags, and assigned owner—ensuring seamless handoff between analysts without data loss.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A watchlist item
Why it's wrong here
A watchlist item stores structured tabular data—such as IP addresses, hostnames, or account names—used for correlation and enrichment during querying. It is not designed for free-form narrative notes; while you could technically add a column with text, it lacks the timestamped, auditable, per-incident comment threading that investigation notes require. Watchlists are optimized for lookup performance and schema-driven matching, not for preserving an evolving investigative story. Therefore, a watchlist item does not meet the stated requirement to preserve investigation notes in a meaningful, accessible way.
- ✗
A workbook parameter
Why it's wrong here
A workbook parameter is a UI element used to pass user input—such as a time range, subscription, or property filter—into queries that populate workbook visualizations. Parameters are ephemeral, hold a single scalar value, and exist only for the session in which the workbook is rendered. They are not a storage location for persisted notes; closing the workbook or refreshing the page discards any parameter value. Although an analyst might use a parameter to filter to a specific incident, this does not create any lasting record of their investigation notes, making it unsuitable for the stated preservation requirement.
- ✗
A data connector
Why it's wrong here
A data connector is a configuration that brings data into Sentinel from a source like Microsoft Entra ID, Office 365, or a custom API. It defines the data source, authentication, and log ingestion pipeline, but it has no concept of storing investigation notes. Connectors govern how raw telemetry flows into Log Analytics workspaces; they do not provide a user-facing surface for adding comments or documenting an incident's narrative. Preserving notes on a connector would be impossible because connectors operate at the infrastructure layer and have no incident-scoped metadata store, so this option is clearly incorrect for the requirement.
- ✓
The Sentinel incident
Why this is correct
The Microsoft Sentinel incident is the correct place to preserve investigation notes because incidents have a dedicated comments section and audit history that persist with the case. Each comment is timestamped and attributed to the analyst, creating an immutable, chronological record of observations, hypotheses, and actions taken. This documentation is retained as part of the incident's metadata, is visible to all team members investigating the incident, and can be exported or queried via APIs for compliance or post-incident review. Storing notes on the incident directly ties the documentation to the investigation's lifecycle, ensuring no context is lost when the incident is closed or reopened.
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.