AZ-500 Manage identity and access Practice Question
A Sentinel rule using a threat intelligence table fires on stale indicators that expired last week. What should be added to the query?
⚠ Common exam trap
It's easy for candidates to think removing a column (project-away) or sorting data addresses the root cause of stale data, rather than recognizing that a row-level filter is required to exclude expired indicators.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A filter for active indicators whose expiration time is in the future
The rule fires on stale indicators because the query lacks a filter to exclude expired threat intelligence entries. Adding a filter for active indicators whose expiration time is in the future ensures that only current, valid indicators trigger the rule, preventing false positives from outdated data.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A union with Usage
Why it's wrong here
A union with Usage merges rows from the ThreatIntelligenceIndicator table with the Usage table, which tracks workspace data usage metrics. This operation does not constrain the result set to active indicators; instead it introduces unrelated, non-indicator rows and requires matching column schemas, potentially causing malformed results or query failure. Because it lacks any time-bounded filter on indicator expiration, a rule based solely on this union would fire on stale or inactive intelligence entries and fail the stated requirement.
- ✗
A sort by Description
Why it's wrong here
Sorting by Description reorders records alphabetically based on the indicator description field, but it applies zero row-level filtering. Expired indicators, inactive indicators, and even deleted or superseded entries all remain in the result set, so the rule would generate alerts for indicators that should no longer match. This operator is purely for presentation and cannot implement the required active, future-expiration selection.
- ✗
A project-away of ConfidenceScore
Why it's wrong here
The project-away operator removes the ConfidenceScore column from the output schema, which is useful for reducing data but does not filter which rows are returned. Without a predicate on ExpirationDateTime to exclude expired indicators, the query still includes every row in the table, including inactive and obsolete entities. Accordingly, this projection alone cannot satisfy the requirement; the rule would produce the same row set as the original table, just with fewer columns.
- ✓
A filter for active indicators whose expiration time is in the future
Why this is correct
The correct query filters the ThreatIntelligenceIndicator table to rows where the indicator's expiration time is later than the current time (ExpirationDateTime > now()) and where the indicator's action status is active, thereby including only indicators that are currently valid and in use. This ensures the rule matches only threat intelligence that is still relevant, avoiding alerts from indicators that have expired or been deactivated. In Sentinel you would typically combine this filter with the TI map data and set the rule's query to evaluate at runtime using now(), so the freshness is automatically enforced.
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.