Courseiva

AZ-500 Manage identity and access Practice Question

A Sentinel watchlist contains high-value administrator accounts. Which KQL pattern best uses it in a detection rule?

⚠ Common exam trap

Many exam-takers confuse a watchlist as a static data source that can replace log tables, rather than understanding it as a reference dataset that must be explicitly joined or filtered within a KQL query to be useful in detection rules.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Load the watchlist with _GetWatchlist() and join or filter SigninLogs by the account identifier

The `_GetWatchlist()` function in KQL allows you to dynamically load a Sentinel watchlist into a query. By joining or filtering `SigninLogs` against the watchlist's account identifier field, you can create a detection rule that triggers only when a high-value administrator account (defined in the watchlist) performs a sign-in, enabling precise, automated alerting without manual intervention.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Load the watchlist with _GetWatchlist() and join or filter SigninLogs by the account identifier

    Why this is correct

    Load the watchlist inside the analytics rule query by calling _GetWatchlist('<alias>'), which returns the watchlist as a KQL table. You can then use a join or a where filter against the SigninLogs table using the account identifier column (for example, UserPrincipalName or UserId) to restrict or enrich the results to only high-value administrator accounts. This executes at query time, so each scheduled run automatically uses the current watchlist contents and triggers alerts only when a matching account produces a sign-in event.

  • ✗

    Export the watchlist to CSV and manually compare it after alerts fire

    Why it's wrong here

    This approach is purely reactive: you wait until alerts have already fired and then manually export the watchlist to CSV and compare entries against the sign-in logs after the fact. It creates no automated correlation in KQL, no scheduled rule enhancement, and no real-time filtering, so high-value admin events can easily be missed or reported too late for response. A manually maintained CSV also diverges from the live watchlist version in Sentinel, so the comparison may be based on stale data and human error, undermining the entire detection requirement.

  • ✗

    Use the watchlist as a replacement for the SigninLogs table

    Why it's wrong here

    A watchlist is reference data, not an activity log: it contains identifiers and metadata such as account names, roles, or tags, but it does not contain sign-in events, timestamps, IP addresses, or user agent details that SigninLogs provides. Replacing the SigninLogs table with a watchlist would eliminate all the telemetry needed for a detection rule, so the query would have nothing to analyze for anomalous behavior. The correct use is to enrich or filter SigninLogs with the watchlist, never to substitute the source table itself.

  • ✗

    Attach the watchlist to a workbook without changing the detection query

    Why it's wrong here

    Attaching the watchlist to an Azure Sentinel workbook only influences what is displayed in the workbook's visualization; it does not alter the underlying analytics rule query that generates alerts. Because the detection query remains unchanged, the watchlist is never referenced with _GetWatchlist() in KQL, so alerts are not filtered or prioritized based on high-value administrator accounts at all. This may help analysts see context interactively, but it fails the requirement to automatically correlate sign-ins with the watchlist in the detection rule itself.

About these practice questions

Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.