Courseiva

AZ-500 Practice Question: Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel

Exhibit

Log Analytics query:
SecurityEvent
| where TimeGenerated > ago(1h)
| where EventID == 4625
| summarize FailedLogins = count() by Account, IpAddress
| where FailedLogins > 10
| project Account, IpAddress, FailedLogins

Refer to the exhibit. You are creating a Microsoft Sentinel scheduled analytics rule using the KQL query shown. The rule is set to run every hour. What will this rule detect?

⚠ Common exam trap

The trap here is that candidates overlook the `summarize` grouping by both `Account` and `IPAddress`, mistakenly thinking the count applies to all IPs combined, or they misinterpret `bin(TimeGenerated, 1h)` as a 24-hour window instead of a 1-hour aggregation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Accounts that have more than 10 failed logins from a specific IP address in the last hour

The KQL query uses `summarize` with `bin(TimeGenerated, 1h)` to count failed logins per account and IP address within 1-hour bins. The `where` clause filters for `ResultType == 50057` (failed logins) and `where count_ > 10` ensures only accounts with more than 10 failed logins from a specific IP in that hour are returned. Since the rule runs every hour, it detects accounts exceeding 10 failed logins from a single IP in the last hour.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Successful logins from a single IP address

    Why it's wrong here

    The query explicitly filters on EventID 4625, which is generated only when a sign-in attempt fails. Successful logins would appear as EventID 4624, so they are excluded before any aggregation occurs. Additionally, the query does not target a single IP address; it groups results by both Account and IpAddress to compute per-pair failure counts.

  • ✓

    Accounts that have more than 10 failed logins from a specific IP address in the last hour

    Why this is correct

    This is the correct answer because the query applies a 1-hour time filter via `TimeGenerated > ago(1h)`, selects only EventID 4625 (failed logons), and then runs `summarize Count = count() by Account, IpAddress`. The final `Count > 10` condition in the `having` clause ensures only account/IP pairs that exceeded 10 failures within that hour are returned, matching the described behavior.

  • ✗

    Total failed logins in the last 24 hours

    Why it's wrong here

    The query restricts events to the last 1 hour using `ago(1h)`, so it cannot report a 24-hour total. The query also does not compute a simple total across all events; instead, it aggregates counts correlated to each account and source IP, and only outputs those exceeding the threshold. Therefore, it would miss failed logins older than an hour and would not produce an overall failed-login count.

  • ✗

    Accounts with more than 10 failed logins from any IP address

    Why it's wrong here

    The grouping by `IpAddress` means the 10-failure threshold is evaluated separately for each source IP address. An account with 6 failed logins from one IP and 6 from another would have 12 total failures, but neither IP alone reaches 10, so the query would not return that account. The query also only counts failures, not logins from any IP as a single aggregate.

About these practice questions

One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.