Courseiva

AZ-500 Practice Question: Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel

You are using Microsoft Sentinel to monitor security events. You need to create a custom analytics rule that detects when a user account is added to a privileged group. The rule should run every 5 minutes and generate an incident. Which query language and data source should you use?

⚠ Common exam trap

The trap here is assuming that SecurityEvent or AzureActivity tables contain Microsoft Entra ID group changes, but those are in AuditLogs.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

KQL against the AuditLogs table.

To detect user account additions to privileged groups, you need Microsoft Entra ID audit logs, which are stored in the AuditLogs table in Microsoft Sentinel. KQL is the query language for analytics rules. The AuditLogs table captures group management activities, including additions to privileged roles. The rule can be scheduled to run every 5 minutes and generate incidents when the condition is met.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    KQL against the AzureActivity table.

    Why it's wrong here

    The AzureActivity table contains Azure Resource Manager operational logs, such as resource creation or deletion, but not Microsoft Entra ID group membership changes. Adding a user to a privileged group is an Microsoft Entra ID operation, logged in AuditLogs. Thus, AzureActivity is not suitable for this detection.

  • ✓

    KQL against the AuditLogs table.

    Why this is correct

    The AuditLogs table in Microsoft Sentinel contains Microsoft Entra ID (Microsoft Entra ID) audit logs, which include events for adding members to groups, especially privileged groups. This is the correct data source for detecting user account additions to privileged groups. KQL is the query language used in Sentinel analytics rules, and this table provides the necessary events.

  • ✗

    KQL against the SigninLogs table.

    Why it's wrong here

    The SigninLogs table contains sign-in events, not group membership changes. While it can detect suspicious sign-ins, it does not record when a user is added to a group. Therefore, it cannot be used to detect the specified activity. The AuditLogs table is the correct source for group membership changes.

  • ✗

    KQL against the SecurityEvent table.

    Why it's wrong here

    The SecurityEvent table contains Windows security events, but user account additions to privileged groups are typically logged in Microsoft Entra ID (Microsoft Entra ID) audit logs, not in SecurityEvent. While some on-premises events might be captured, for cloud-only or hybrid scenarios, the AuditLogs table is more appropriate. Using SecurityEvent would miss the relevant events.

About these practice questions

One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.