AZ-500 Practice Question: Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel
Exhibit
SigninLogs
| where TimeGenerated > ago(7d)
| where RiskLevelDuringSignIn in ('medium', 'high')
| extend Country = tostring(LocationDetails.countryOrRegion)
| where Country != 'US'
| summarize SigninCount = count() by UserPrincipalName, Country
| where SigninCount > 3Refer to the exhibit. A Microsoft Sentinel analytics rule uses this KQL query. What is the primary purpose of this rule?
⚠ Common exam trap
Watch out — candidates often confuse 'risky sign-ins from non-US countries' with 'impossible travel' (option C), but impossible travel requires analyzing the time gap between geographically distant sign-ins, which this query does not do.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Detect users with multiple risky sign-ins from non-US countries.
The KQL query filters sign-ins with risk level 'medium' or 'high' from countries other than the US, then counts them per user and filters for users with more than one such sign-in. This directly detects users who have multiple risky sign-ins from non-US countries, making option B correct. The rule does not consider historical sign-in patterns or averages, only the count of risky sign-ins outside the US.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Detect users who have never signed in from the US before.
Why it's wrong here
The analytics rule's query only examines sign-in events within a 7-day lookback window and does not reference any historical baseline of a user's previous sign-in locations. Detecting users who have 'never' signed in from the US would require comparing current locations against an accumulated user profile or an external watchlist of first-ever sign-in geography. Since the query only counts risky sign-ins from non-US countries, it cannot identify a user who has simply never used a US sign-in origin.
- ✓
Detect users with multiple risky sign-ins from non-US countries.
Why this is correct
The rule's KQL query aggregates sign-in logs where the risk level is marked as risky and the location is outside the United States, grouping results by user principal name. When the count of such events exceeds a threshold (for example, more than 3) within the 7-day evaluation period, an alert is triggered. This directly matches the stated detection intent, making it the correct description of the query's behavior.
- ✗
Detect impossible travel patterns between the US and other countries.
Why it's wrong here
Impossible travel detection requires calculating the time difference and physical distance between consecutive sign-in events to determine whether a user could realistically travel between the two locations within that timeframe. This rule simply counts the number of risky sign-ins from non-US countries without examining timestamps, geolocation coordinates, or the speed of movement. Therefore, it cannot identify the temporal or spatial anomaly that defines impossible travel.
- ✗
Detect users whose sign-in count is higher than the average for their region.
Why it's wrong here
The query applies a fixed numeric threshold to the count of risky non-US sign-ins rather than using a regional average or an adaptive baseline. It does not compute the average sign-in count for a user's region, nor does it compare an individual user's count against that average. Alerting based on deviation from a regional mean would require additional statistical analysis, such as using KQL's series functions or a machine learning baseline, which is not present in this rule.
Go deeper
Related to this question
About these practice questions
One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.