AZ-500 Manage identity and access Practice Question
A Sentinel watchlist contains high-value administrator accounts. Which KQL pattern best uses it in a detection rule?
⚠ Common exam trap
Many exam-takers confuse a watchlist as a static data source that can replace log tables, rather than understanding it as a reference dataset that must be explicitly joined or filtered within a KQL query to be useful in detection rules.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Load the watchlist with _GetWatchlist() and join or filter SigninLogs by the account identifier
The `_GetWatchlist()` function in KQL allows you to dynamically load a Sentinel watchlist into a query. By joining or filtering `SigninLogs` against the watchlist's account identifier field, you can create a detection rule that triggers only when a high-value administrator account (defined in the watchlist) performs a sign-in, enabling precise, automated alerting without manual intervention.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Load the watchlist with _GetWatchlist() and join or filter SigninLogs by the account identifier
Why this is correct
Load the watchlist inside the analytics rule query by calling _GetWatchlist('<alias>'), which returns the watchlist as a KQL table. You can then use a join or a where filter against the SigninLogs table using the account identifier column (for example, UserPrincipalName or UserId) to restrict or enrich the results to only high-value administrator accounts. This executes at query time, so each scheduled run automatically uses the current watchlist contents and triggers alerts only when a matching account produces a sign-in event.
- ✗
Export the watchlist to CSV and manually compare it after alerts fire
Why it's wrong here
This approach is purely reactive: you wait until alerts have already fired and then manually export the watchlist to CSV and compare entries against the sign-in logs after the fact. It creates no automated correlation in KQL, no scheduled rule enhancement, and no real-time filtering, so high-value admin events can easily be missed or reported too late for response. A manually maintained CSV also diverges from the live watchlist version in Sentinel, so the comparison may be based on stale data and human error, undermining the entire detection requirement.
- ✗
Use the watchlist as a replacement for the SigninLogs table
Why it's wrong here
A watchlist is reference data, not an activity log: it contains identifiers and metadata such as account names, roles, or tags, but it does not contain sign-in events, timestamps, IP addresses, or user agent details that SigninLogs provides. Replacing the SigninLogs table with a watchlist would eliminate all the telemetry needed for a detection rule, so the query would have nothing to analyze for anomalous behavior. The correct use is to enrich or filter SigninLogs with the watchlist, never to substitute the source table itself.
- ✗
Attach the watchlist to a workbook without changing the detection query
Why it's wrong here
Attaching the watchlist to an Azure Sentinel workbook only influences what is displayed in the workbook's visualization; it does not alter the underlying analytics rule query that generates alerts. Because the detection query remains unchanged, the watchlist is never referenced with _GetWatchlist() in KQL, so alerts are not filtered or prioritized based on high-value administrator accounts at all. This may help analysts see context interactively, but it fails the requirement to automatically correlate sign-ins with the watchlist in the detection rule itself.
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.