AZ-500 Practice Question: Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel
Exhibit
Log Analytics query: SecurityEvent | where TimeGenerated > ago(1h) | where EventID == 4625 | summarize FailedLogins = count() by Account, IpAddress | where FailedLogins > 10 | project Account, IpAddress, FailedLogins
Refer to the exhibit. You are creating a Microsoft Sentinel scheduled analytics rule using the KQL query shown. The rule is set to run every hour. What will this rule detect?
⚠ Common exam trap
The trap here is that candidates overlook the `summarize` grouping by both `Account` and `IPAddress`, mistakenly thinking the count applies to all IPs combined, or they misinterpret `bin(TimeGenerated, 1h)` as a 24-hour window instead of a 1-hour aggregation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Accounts that have more than 10 failed logins from a specific IP address in the last hour
The KQL query uses `summarize` with `bin(TimeGenerated, 1h)` to count failed logins per account and IP address within 1-hour bins. The `where` clause filters for `ResultType == 50057` (failed logins) and `where count_ > 10` ensures only accounts with more than 10 failed logins from a specific IP in that hour are returned. Since the rule runs every hour, it detects accounts exceeding 10 failed logins from a single IP in the last hour.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Successful logins from a single IP address
Why it's wrong here
The query explicitly filters on EventID 4625, which is generated only when a sign-in attempt fails. Successful logins would appear as EventID 4624, so they are excluded before any aggregation occurs. Additionally, the query does not target a single IP address; it groups results by both Account and IpAddress to compute per-pair failure counts.
- ✓
Accounts that have more than 10 failed logins from a specific IP address in the last hour
Why this is correct
This is the correct answer because the query applies a 1-hour time filter via `TimeGenerated > ago(1h)`, selects only EventID 4625 (failed logons), and then runs `summarize Count = count() by Account, IpAddress`. The final `Count > 10` condition in the `having` clause ensures only account/IP pairs that exceeded 10 failures within that hour are returned, matching the described behavior.
- ✗
Total failed logins in the last 24 hours
Why it's wrong here
The query restricts events to the last 1 hour using `ago(1h)`, so it cannot report a 24-hour total. The query also does not compute a simple total across all events; instead, it aggregates counts correlated to each account and source IP, and only outputs those exceeding the threshold. Therefore, it would miss failed logins older than an hour and would not produce an overall failed-login count.
- ✗
Accounts with more than 10 failed logins from any IP address
Why it's wrong here
The grouping by `IpAddress` means the 10-failure threshold is evaluated separately for each source IP address. An account with 6 failed logins from one IP and 6 from another would have 12 total failures, but neither IP alone reaches 10, so the query would not return that account. The query also only counts failures, not logins from any IP as a single aggregate.
Go deeper
Related to this question
About these practice questions
One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.