Question 217 of 194
Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel →hardMultiple ChoiceObjective-mapped
Writing a KQL Query to Detect Brute Force Sign-In Attempts in Microsoft Sentinel
You are a security analyst using Microsoft Sentinel. You need to create an analytics rule that triggers an incident when more than 10 failed sign-ins occur from the same IP address within 5 minutes. The rule should use a KQL query. Which query should you use?
Quick Answer
The correct query is SigninLogs | where ResultType !in ("0","50125") | summarize Count = count() by IPAddress, bin(TimeGenerated, 5m) | where Count > 10. This works because it first filters out successful sign-ins (ResultType 0) and the specific code 50125 (which indicates a device authentication that isn't a true failure), then groups the remaining failed attempts by IP address within a 5-minute window using the bin() function, and finally keeps only those groups where the count exceeds 10. On the AZ-500 exam, this question tests your ability to build a KQL query for a brute force detection rule in Microsoft Sentinel, a common scenario for security analysts. A frequent trap is confusing TimeGenerated with time-generated (which is not a valid column) or mistakenly using make-series for simple aggregation. Remember the mnemonic "Filter, Group, Bin, Threshold" — first filter for failures, group by IP, bin the time, then apply the count condition.
⚠ Common exam trap
Many exam-takers confuse the ResultType values, mistakenly filtering for successful sign-ins (ResultType == '0') instead of failed sign-ins, or they use `make-series` which is designed for time-series analysis rather than event counting with threshold filtering.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SigninLogs | where ResultType !in ("0","50125") // failed attempts | summarize Count = count() by IPAddress, bin(TimeGenerated, 5m) | where Count > 10
It filters for failed sign-ins by excluding successful results (ResultType '0' and '50125', where '50125' is a non-failure code), then uses `summarize` with `bin(TimeGenerated, 5m)` to count failed attempts per IP address within 5-minute windows, and finally filters for counts exceeding 10. This directly meets the requirement to trigger an incident when more than 10 failed sign-ins occur from the same IP within 5 minutes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
SigninLogs | where ResultType !in ("0","50125") // failed attempts | summarize Count = count() by IPAddress, bin(TimeGenerated, 5m) | where Count > 10
Why this is correct
This query correctly groups failed sign-ins by IP and 5-minute bin, and filters for >10.
- ✗
SigninLogs | where ResultType != "0" | make-series Count=count() default=0 on TimeGenerated from ago(5m) to now() step 5m by IPAddress
Why it's wrong here
make-series is for creating time series data, not for simple count filtering.
- ✗
SigninLogs | where ResultType == "0" | summarize Count = count() by IPAddress, bin(TimeGenerated, 5m) | where Count > 10
Why it's wrong here
Filters for successful sign-ins (ResultType=="0"), not failed ones.
- ✗
SigninLogs | where ResultType == "0" | summarize Count = count() by IPAddress, bin(time-generated, 5m) | where Count > 10
Why it's wrong here
Uses incorrect column name 'time-generated' and filters for successful sign-ins only.
About these practice questions
Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
2 more ways this is tested on AZ-500
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Refer to the exhibit. You are creating a Microsoft Sentinel scheduled analytics rule using the KQL query shown. The rule is set to run every hour. What will this rule detect?
medium- A.Successful logins from a single IP address
- ✓ B.Accounts that have more than 10 failed logins from a specific IP address in the last hour
- C.Total failed logins in the last 24 hours
- D.Accounts with more than 10 failed logins from any IP address
Why B: The KQL query uses `summarize` with `bin(TimeGenerated, 1h)` to count failed logins per account and IP address within 1-hour bins. The `where` clause filters for `ResultType == 50057` (failed logins) and `where count_ > 10` ensures only accounts with more than 10 failed logins from a specific IP in that hour are returned. Since the rule runs every hour, it detects accounts exceeding 10 failed logins from a single IP in the last hour.
Variation 2. Refer to the exhibit. You are analyzing a KQL query in Microsoft Sentinel. The query returns a list of IP addresses that have attempted to sign in more than 10 times in the last day. You notice that the query does not filter out successful sign-ins. You need to modify the query to count only failed sign-in attempts. What should you add?
medium- A.Add '| where Status == "Failure"' before the summarize
- B.Add '| where Result == "Failure"' before the summarize
- C.Add '| where ResultType == "0"' before the summarize
- ✓ D.Add '| where ResultType != "0"' before the summarize
Why D: In Microsoft Sentinel, the KQL query for sign-in logs uses the 'ResultType' field to indicate success or failure. A 'ResultType' of '0' represents a successful sign-in, while any non-zero value indicates a failure. Therefore, to count only failed sign-in attempts, you must filter with '| where ResultType != "0"' before the summarize operator. Option D correctly applies this filter, excluding successful sign-ins and ensuring the count reflects only failures.
Last reviewed: Jul 4, 2026
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.
Question Discussion
Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.
Sign in to join the discussion.