Courseiva

AZ-500 Manage identity and access Practice Question

A Sentinel analyst needs to preserve investigation notes, related entities, and ownership while escalating a case to another analyst. Which object should be updated?

⚠ Common exam trap

Test-takers frequently confuse operational artifacts (watchlists, workbooks, connectors) with the incident object that actually holds case-specific metadata, leading them to select a static or non-persistent option instead of the dynamic incident record.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The Sentinel incident

The Sentinel incident object is the correct entity to update because it serves as the central container for investigation notes, related entities, and ownership assignments during case escalation. Updating the incident preserves the full investigation context—including comments, tags, and assigned owner—ensuring seamless handoff between analysts without data loss.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A watchlist item

    Why it's wrong here

    A watchlist item stores structured tabular data—such as IP addresses, hostnames, or account names—used for correlation and enrichment during querying. It is not designed for free-form narrative notes; while you could technically add a column with text, it lacks the timestamped, auditable, per-incident comment threading that investigation notes require. Watchlists are optimized for lookup performance and schema-driven matching, not for preserving an evolving investigative story. Therefore, a watchlist item does not meet the stated requirement to preserve investigation notes in a meaningful, accessible way.

  • ✗

    A workbook parameter

    Why it's wrong here

    A workbook parameter is a UI element used to pass user input—such as a time range, subscription, or property filter—into queries that populate workbook visualizations. Parameters are ephemeral, hold a single scalar value, and exist only for the session in which the workbook is rendered. They are not a storage location for persisted notes; closing the workbook or refreshing the page discards any parameter value. Although an analyst might use a parameter to filter to a specific incident, this does not create any lasting record of their investigation notes, making it unsuitable for the stated preservation requirement.

  • ✗

    A data connector

    Why it's wrong here

    A data connector is a configuration that brings data into Sentinel from a source like Microsoft Entra ID, Office 365, or a custom API. It defines the data source, authentication, and log ingestion pipeline, but it has no concept of storing investigation notes. Connectors govern how raw telemetry flows into Log Analytics workspaces; they do not provide a user-facing surface for adding comments or documenting an incident's narrative. Preserving notes on a connector would be impossible because connectors operate at the infrastructure layer and have no incident-scoped metadata store, so this option is clearly incorrect for the requirement.

  • ✓

    The Sentinel incident

    Why this is correct

    The Microsoft Sentinel incident is the correct place to preserve investigation notes because incidents have a dedicated comments section and audit history that persist with the case. Each comment is timestamped and attributed to the analyst, creating an immutable, chronological record of observations, hypotheses, and actions taken. This documentation is retained as part of the incident's metadata, is visible to all team members investigating the incident, and can be exported or queried via APIs for compliance or post-incident review. Storing notes on the incident directly ties the documentation to the investigation's lifecycle, ensuring no context is lost when the incident is closed or reopened.

About these practice questions

Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.