AZ-500 Practice Question: Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel
Your company uses Microsoft Sentinel to monitor Azure resources. A new analytics rule is created to detect anomalous access to storage accounts. The rule runs every 5 minutes and looks at the last 15 minutes of data. After deploying, the rule generates no alerts even though you suspect there are anomalies. What is the most likely issue?
⚠ Common exam trap
A common mix-up: candidates assume a rule's frequency or lookback period is the root cause, but Microsoft Sentinel allows the frequency to be shorter than the lookback period (e.g., 5 min frequency with 15 min lookback) to enable sliding window analysis; the real issue is almost always incorrect query logic or missing entity mappings.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The rule query logic is incorrect or the entities are not properly mapped.
The most likely issue is that the rule query logic is incorrect or the entities are not properly mapped. In Microsoft Sentinel, an analytics rule uses a KQL query to detect anomalies; if the query syntax is wrong, the logic fails to match the expected data patterns, or the entity mappings (e.g., Account, IP, Host) are misconfigured, the rule will not generate alerts even when anomalous activity exists. Without correct entity mapping, the rule cannot correlate events or trigger incidents, resulting in zero alerts despite underlying anomalies.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The rule is not enabled.
Why it's wrong here
In Microsoft Sentinel, an analytics rule must have its 'Status' set to Enabled to execute on the defined schedule. If the rule is accidentally disabled, Sentinel will not run the query at all, so no alerts are generated. However, in a troubleshooting scenario, you would first confirm the rule is active in the workspace; if it is, this is not the cause, and the more subtle issue is likely in the rule's query or its entity mapping.
- ✓
The rule query logic is incorrect or the entities are not properly mapped.
Why this is correct
For a scheduled analytics rule, an alert is only created when the KQL query returns at least one row. The most common reason for silence is that the query contains incorrect logic—such as referencing a non-existent table, filtering on misspelled columns, or using a where clause that never evaluates to true—which results in zero matching records. Improper entity mapping does not directly prevent alert generation, but it can cause alerts to lack the required entity fields, which may interfere with incident creation and automation, making it appear as though the rule is failing.
- ✗
The rule severity is set too low.
Why it's wrong here
The severity field (Informational, Low, Medium, High) is purely a classification label used for triage, dashboards, and notification priorities; it imposes no restriction on rule execution or alert generation in Microsoft Sentinel. A rule set to 'Low' will produce alerts and incidents exactly like a 'High' rule, assuming the query returns matching data. Therefore, a low severity value is never the reason alerts are missing.
- ✗
The rule query frequency is longer than the data lookback period.
Why it's wrong here
In Sentinel's scheduled rule settings, the 'Run query every' (frequency) and 'Lookup data from the last' (lookback) are independent parameters. The query always evaluates the entire lookback window regardless of how often the rule runs, so a 5-minute frequency with a 15-minute lookback is a perfectly valid configuration that does not create data gaps. Even if frequency exceeds lookback, the rule still covers that period, so this is not a root cause of missed alerts; confusion often arises from conflating frequency with the query coverage window.
Go deeper
Related to this question
About these practice questions
This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.