Courseiva

AZ-500 Manage identity and access Practice Question

A SOC wants a Sentinel rule to include account, host, and IP entities so analysts can pivot during investigation. What should be configured in the analytics rule?

⚠ Common exam trap

A common mix-up: candidates confuse 'custom details' with 'entity mapping' because both involve extracting data from query results, but custom details only add flat key-value pairs to the alert, whereas entity mapping creates structured, pivotable objects that the investigation graph can traverse.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Entity mapping

Entity mapping is the correct configuration because it explicitly links the analytics rule's results to known entity types (account, host, IP) in Microsoft Sentinel. This enables analysts to pivot directly from an alert to related entities in the investigation graph, enriching context without manual cross-referencing. Without entity mapping, the rule would generate alerts but lack the structured entity data needed for seamless pivot actions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Custom details only

    Why it's wrong here

    Custom details in an Azure Sentinel analytics rule let you extract event fields and show them as key-value pairs in the alert, but they do not create structured entities in the alert schema. Those extracted values cannot be used by entity pages, incident investigation, or UEBA behavior analytics, so an account, host, or IP would remain an untyped string rather than a recognized entity. Therefore, custom details alone are not a valid way to meet the requirement that these three values be present as entities.

  • ✓

    Entity mapping

    Why this is correct

    Entity mapping is the correct mechanism because it explicitly binds event fields to typed entity objects in the alert, assigning one field to the Account, another to the Host, and another to the IP. In the rule's alert enrichment section, the SOC can map the exact event properties to entity identifiers such as Account Name, Host Hostname, and IP Address. Once mapped, Microsoft Sentinel stores these as real entities, enabling correlation across alerts, entity pages, and incident enrichment.

  • ✗

    Suppression rules

    Why it's wrong here

    Alert suppression rules in Sentinel control when duplicate alerts are generated after an initial match, usually by suppressing alerts for a configured time window to reduce noise. Suppression is an operational control meant to limit alert fatigue and does not enrich or alter the alert content. It cannot add account, host, or IP values to an alert, so suppression rules have no effect on entity inclusion and fail the stated requirement.

  • ✗

    Workbook parameters

    Why it's wrong here

    Workbook parameters are user-facing inputs such as dropdowns or time pickers that make Sentinel workbooks interactive by changing the underlying Kusto queries. They exist in the reporting and visualization layer and do not interact with the alert creation pipeline or the analytics rule schema. Because they cannot modify an alert's properties or entities, workbook parameters cannot be used to include account, host, and IP values in a generated alert.

About these practice questions

This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.