Courseiva

AZ-500 Manage identity and access Practice Question

A SOC analyst needs a Sentinel query that detects multiple failed sign-ins followed by a successful sign-in for the same user. Which table is the best primary source?

⚠ Common exam trap

A common mix-up: candidates confuse AzureActivity (which logs administrative actions) with sign-in logs, or assume SecurityAlert contains raw event data, when in fact only SigninLogs provides the granular authentication events needed for this detection pattern.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

SigninLogs

SigninLogs is the correct primary source because it captures both failed and successful user sign-in events from Microsoft Entra ID, including interactive and non-interactive logins. This table provides the necessary fields like ResultType (e.g., 0 for success, 50125 for failure) and UserPrincipalName to build a KQL query that detects a sequence of failed sign-ins followed by a successful one for the same user.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    SecurityAlert

    Why it's wrong here

    The SecurityAlert table in Azure Sentinel stores high-fidelity detections that are already generated by analytics rules or Microsoft security services, not the raw sign-in attempts. Querying it would surface pre-triaged alerts that may not include every failed login, lacking the granular per-attempt status fields like `ResultType` and `ResultDescription` that are essential for counting multiple failed authentication events. To directly detect such patterns, you must query the underlying SigninLogs data.

  • ✗

    AzureActivity

    Why it's wrong here

    The AzureActivity table captures only control-plane operations, such as creating resources, modifying configurations, or assigning roles, not user authentication events. Failed sign-in attempts or password validation outcomes are never written here, because that telemetry belongs to the Microsoft Entra ID authentication layer and is stored in SigninLogs. Therefore, an AzureActivity query cannot detect multiple failed logons; it would miss all authentication-level data despite appearing as a broad audit log.

  • ✗

    DeviceNetworkEvents

    Why it's wrong here

    DeviceNetworkEvents logs network connections from endpoints via Microsoft Defender for Endpoint, tracking processes and remote IPs for outbound/inbound traffic. It does not contain Microsoft Entra ID sign-in attempts, so it cannot provide authentication status codes or failed logon events. While it can be correlated after a compromise to spot suspicious network behavior, it is not suitable for detecting multiple failed sign-ins, which occur at the identity provider layer, not the device network layer.

  • ✓

    SigninLogs

    Why this is correct

    SigninLogs stores every Microsoft Entra ID sign-in attempt, including both interactive and non-interactive logons, with detailed attributes such as `ResultType`, `ResultDescription`, `IPAddress`, and `UserPrincipalName`. By using a Kusto query to filter on error codes indicating failure (e.g., `ResultType != 0` or specific codes like `50053`), you can aggregate attempts with `summarize count() by UserPrincipalName` over a sliding time window to identify multiple failed logons. This is the definitive table for detecting brute-force or password-spray patterns in Azure Sentinel.

About these practice questions

One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.