AZ-500 Practice Question: Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel
Exhibit
Refer to the exhibit. ```kusto // KQL query used in a Microsoft Sentinel scheduled analytics rule SigninLogs | where TimeGenerated > ago(1h) | where ResultType == "50057" // User account is disabled | where IPAddress !in (dynamic(["10.0.0.1", "10.0.0.2"])) | project TimeGenerated, UserPrincipalName, IPAddress, AppDisplayName ```
Refer to the exhibit. You are reviewing a scheduled analytics rule in Microsoft Sentinel that uses the KQL query shown. The rule is configured to run every hour. A security analyst reports that the rule is generating too many incidents. What is the most likely cause?
⚠ Common exam trap
The trap here is that candidates often blame the rule frequency (Option A) or the time range (Option C) without realizing that the core issue is the query's lack of IP filtering, which is a common misconfiguration in Sentinel analytics rules.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The query does not filter out known safe IP addresses sufficiently.
The query likely uses a broad filter for sign-in events without excluding known safe IP addresses (e.g., corporate VPNs, trusted services). This causes every sign-in from those IPs to generate an incident, overwhelming the rule with false positives. The rule's frequency (every hour) is not the issue; the query logic is insufficiently scoped.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The rule is configured to run too frequently.
Why it's wrong here
The rule's schedule of once per hour is a standard cadence for a SigninLogs-based detection and does not by itself cause additional incidents to match. Alert frequency only determines when the query is executed; it has no effect on the query's match criteria or the volume of results returned. False-positive volume is driven by the presence of legitimate disabled-account sign-ins from many IPs, not by how often the rule runs.
- ✓
The query does not filter out known safe IP addresses sufficiently.
Why this is correct
The query excludes only two specific IP addresses, which leaves all other internal or trusted IPs subject to creating an incident when a disabled account signs in. Because disabled-account sign-in events are often generated by old service accounts, scheduled tasks, or users who have not been offboarded, the rule should apply an allowlist of corporate egress ranges or a blocklist/allowlist combination. Without a sufficiently broad safe-IP filter, the rule will repeatedly alert on legitimate activity and drown out genuinely suspicious disabled-account access.
- ✗
The query uses 'ago(1h)' which includes data from the previous hour, causing duplicate incidents.
Why it's wrong here
Using ago(1h) is a correct lookback for a rule that runs hourly; it limits results to the last hour and is not the reason the rule is noisy. Even if there is slight overlap at the boundary between runs, incident grouping in the scheduled query rule normally deduplicates the same underlying event, so this does not explain why every disabled-account sign-in from a wide range of IPs becomes its own incident. The real problem is that the query's IP filter is too narrow to exclude the many known-good source addresses.
- ✗
The query has a syntax error that causes all sign-ins to match.
Why it's wrong here
A syntax error would prevent the scheduled query from being saved or executed, but the query is valid KQL as written and therefore cannot be the cause of all sign-ins matching. Even when a query is syntactically correct, it can still produce excessive results because of insufficient filtering. The issue in this rule is not malformed syntax but too permissive match logic that lacks a comprehensive known-IP allowlist.
Go deeper
Related to this question
About these practice questions
One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.