Courseiva

AZ-500 Practice Question: Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel

Exhibit

Refer to the exhibit.

```kusto
// KQL query used in a Microsoft Sentinel scheduled analytics rule
SigninLogs
| where TimeGenerated > ago(1h)
| where ResultType == "50057"  // User account is disabled
| where IPAddress !in (dynamic(["10.0.0.1", "10.0.0.2"]))
| project TimeGenerated, UserPrincipalName, IPAddress, AppDisplayName
```

Refer to the exhibit. You are reviewing a scheduled analytics rule in Microsoft Sentinel that uses the KQL query shown. The rule is configured to run every hour. A security analyst reports that the rule is generating too many incidents. What is the most likely cause?

⚠ Common exam trap

The trap here is that candidates often blame the rule frequency (Option A) or the time range (Option C) without realizing that the core issue is the query's lack of IP filtering, which is a common misconfiguration in Sentinel analytics rules.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The query does not filter out known safe IP addresses sufficiently.

The query likely uses a broad filter for sign-in events without excluding known safe IP addresses (e.g., corporate VPNs, trusted services). This causes every sign-in from those IPs to generate an incident, overwhelming the rule with false positives. The rule's frequency (every hour) is not the issue; the query logic is insufficiently scoped.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The rule is configured to run too frequently.

    Why it's wrong here

    The rule's schedule of once per hour is a standard cadence for a SigninLogs-based detection and does not by itself cause additional incidents to match. Alert frequency only determines when the query is executed; it has no effect on the query's match criteria or the volume of results returned. False-positive volume is driven by the presence of legitimate disabled-account sign-ins from many IPs, not by how often the rule runs.

  • ✓

    The query does not filter out known safe IP addresses sufficiently.

    Why this is correct

    The query excludes only two specific IP addresses, which leaves all other internal or trusted IPs subject to creating an incident when a disabled account signs in. Because disabled-account sign-in events are often generated by old service accounts, scheduled tasks, or users who have not been offboarded, the rule should apply an allowlist of corporate egress ranges or a blocklist/allowlist combination. Without a sufficiently broad safe-IP filter, the rule will repeatedly alert on legitimate activity and drown out genuinely suspicious disabled-account access.

  • ✗

    The query uses 'ago(1h)' which includes data from the previous hour, causing duplicate incidents.

    Why it's wrong here

    Using ago(1h) is a correct lookback for a rule that runs hourly; it limits results to the last hour and is not the reason the rule is noisy. Even if there is slight overlap at the boundary between runs, incident grouping in the scheduled query rule normally deduplicates the same underlying event, so this does not explain why every disabled-account sign-in from a wide range of IPs becomes its own incident. The real problem is that the query's IP filter is too narrow to exclude the many known-good source addresses.

  • ✗

    The query has a syntax error that causes all sign-ins to match.

    Why it's wrong here

    A syntax error would prevent the scheduled query from being saved or executed, but the query is valid KQL as written and therefore cannot be the cause of all sign-ins matching. Even when a query is syntactically correct, it can still produce excessive results because of insufficient filtering. The issue in this rule is not malformed syntax but too permissive match logic that lacks a comprehensive known-IP allowlist.

About these practice questions

One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.