AZ-500 Practice Question: Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel
Your organization uses Microsoft Sentinel for security information and event management (SIEM). You need to create a custom analytic rule that triggers an incident when a user signs in from an unfamiliar location. Which data source should you use?
⚠ Common exam trap
A common mix-up: candidates confuse Microsoft Entra ID Audit Logs (which track configuration changes) with Sign-in Logs (which track authentication events), leading them to select the audit logs for a sign-in behavior detection rule.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Entra ID Sign-in Logs
Microsoft Entra ID Sign-in Logs contain detailed information about user sign-in events, including location data. A custom analytic rule in Microsoft Sentinel can use these logs to detect sign-ins from unfamiliar locations by comparing the location against a user's typical sign-in pattern, which is a common UEBA (User and Entity Behavior Analytics) scenario.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Azure Activity Logs
Why it's wrong here
Azure Activity Log captures subscription-level control plane operations such as resource creation, deletion, and configuration changes, not user authentication events. While it shows the caller's identity, it lacks critical sign-in metadata like client IP, device, and sign-in location. Therefore, it cannot support unfamiliar sign-in detection. This is why the Activity Log is not the correct source for this use case.
- ✓
Microsoft Entra ID Sign-in Logs
Why this is correct
Microsoft Entra ID Sign-in Logs record every authentication attempt for interactive and non-interactive sign-ins, including the client IP, approximate geolocation, browser/device, and conditional access results. These logs are designed for identity security scenarios, and when streamed to Microsoft Sentinel they enable analytics rules for unfamiliar sign-in detection. The location data is essential, making these logs the correct answer. This is why Sign-in Logs are the appropriate data source.
- ✗
Microsoft Entra ID Audit Logs
Why it's wrong here
Microsoft Entra ID Audit Logs focus exclusively on directory management events, such as creating or updating users, assigning roles, and changing tenant settings. They do not capture individual authentication events, nor do they include sign-in IP addresses or geographic location, so they cannot indicate where a sign-in originated. Without that location metadata, Audit Logs are useless for detecting unfamiliar sign-in activity. Thus, this option is incorrect.
- ✗
Microsoft 365 Defender Alerts
Why it's wrong here
Microsoft 365 Defender Alerts are generated by detection engines and represent specific threats or suspicious activities, such as a possible attempt to access a compromised account. They do not offer a raw, comprehensive log of every sign-in with its location; instead, they abstract away the underlying telemetry. To run a custom query on sign-in location and detect unfamiliar sign-ins, you need the raw sign-in logs, not processed alerts. Therefore, Defender Alerts are not the correct answer here.
Go deeper
Related to this question
About these practice questions
One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.