You are a security analyst using Microsoft Sentinel. You need to create an analytics rule that triggers an incident when more than 10 failed sign-ins occur from the same IP address within 5 minutes. The rule should use a KQL query. Which query should you use?
This query correctly groups failed sign-ins by IP and 5-minute bin, and filters for >10.
Why this answer
It filters for failed sign-ins by excluding successful results (ResultType '0' and '50125', where '50125' is a non-failure code), then uses `summarize` with `bin(TimeGenerated, 5m)` to count failed attempts per IP address within 5-minute windows, and finally filters for counts exceeding 10. This directly meets the requirement to trigger an incident when more than 10 failed sign-ins occur from the same IP within 5 minutes.
Exam trap
The trap here is that candidates often confuse the ResultType values, mistakenly filtering for successful sign-ins (ResultType == '0') instead of failed sign-ins, or they use `make-series` which is designed for time-series analysis rather than event counting with threshold filtering.
How to eliminate wrong answers
Option B is wrong because `make-series` creates a time series with default values, which is not appropriate for counting discrete events and does not filter for failed sign-ins (it includes all ResultType values except '0'). Option C is wrong because it filters for successful sign-ins (`ResultType == '0'`), which is the opposite of what is needed. Option D is wrong because it filters for successful sign-ins (`ResultType == '0'`) and uses an incorrect field name `time-generated` (should be `TimeGenerated`), which would cause the query to fail or return no results.