AZ-500 Practice Question: Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel
Exhibit
SecurityAlert | where TimeGenerated > ago(7d) | summarize Count = count() by AlertName, AlertSeverity | top 10 by Count desc
Refer to the exhibit. A security analyst runs this KQL query in Microsoft Sentinel. What is the purpose of this query?
⚠ Common exam trap
A common mix-up: candidates confuse aggregation (`summarize`) with filtering or listing, leading them to choose options that describe simple filtering (A, C) or a different aggregation (D) instead of recognizing the top-N grouping by alert name and severity.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
To list the top 10 most frequent alert names along with their severity over the last 7 days.
The KQL query uses the `summarize` operator to group alerts by `AlertName` and `Severity`, then sorts by `count_` in descending order and takes the top 10 results. This produces a list of the 10 most frequent alert names along with their severity over the last 7 days, matching option B.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
To list all alerts with severity 'High' in the last 7 days.
Why it's wrong here
The query does not apply a severity filter, so it cannot be limited to 'High' alerts. It summarizes all alert names and severities and returns the top 10 by count, which includes alerts of every severity level and produces aggregated counts rather than individual alerts. Thus, this statement incorrectly describes the query's filter and output format.
- ✓
To list the top 10 most frequent alert names along with their severity over the last 7 days.
Why this is correct
The query groups alert records by AlertName and Severity using summarize, counts the occurrences in each combination, and applies top to rank those combinations descending by count. This returns the ten most frequent alert-name/severity pairs over the rolling 7-day window, which precisely matches the stated purpose. The inclusion of both fields in the grouping key is essential to the output.
- ✗
To list all alerts generated in the last 7 days.
Why it's wrong here
The query does not enumerate every alert; it condenses raw records via summarize into aggregated groups and then limits the result to ten rows using top. Consequently, it returns only the highest-count alert-name/severity combinations, not a comprehensive list of all alerts generated during the last seven days. The output cardinality is 10, not all matching records.
- ✗
To list the count of alerts per severity for the last 7 days.
Why it's wrong here
The summarize clause groups by both AlertName and Severity, not by Severity alone, so the top 10 results are distinct name/severity pairs rather than severity-level totals. To count alerts per severity, the query would need to group by Severity only, and a top 10 limit would be unnecessary if the intent were simply to show all severity counts. This statement misidentifies the grouping key.
Go deeper
Related to this question
About these practice questions
One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.