Courseiva

AZ-500 Practice Question: Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel

Your security team is investigating a potential data exfiltration incident. They have identified that a user has been downloading large amounts of data from Azure Blob Storage to an external IP address. You need to create a Microsoft Sentinel analytics rule that triggers when more than 1 GB of data is downloaded from a storage account in a single hour. Which KQL query should be the basis of the rule?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

StorageBlobLogs | where OperationName == 'GetBlob' | summarize TotalGB = sum(ResponseBodySize) / 1073741824 by bin(TimeGenerated, 1h) | where TotalGB > 1

It filters StorageBlobLogs to GetBlob operations, sums ResponseBodySize (which is in bytes) over a one-hour bin, converts the total to gigabytes by dividing by 1073741824, and then filters for totals greater than 1 GB — exactly matching the requirement to detect more than 1 GB downloaded per hour. Option B uses avg(ResponseBodySize), which measures the average size of individual downloads rather than the total volume, so it would not detect aggregate exfiltration. Option C checks each individual GetBlob event against 1 GB, missing the scenario where many smaller downloads sum to over 1 GB in an hour. Option D counts the number of GetBlob operations rather than bytes transferred, so it does not measure data volume at all.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    StorageBlobLogs | where OperationName == 'GetBlob' | summarize TotalGB = sum(ResponseBodySize) / 1073741824 by bin(TimeGenerated, 1h) | where TotalGB > 1

    Why this is correct

    This is correct because it sums the ResponseBodySize of all GetBlob operations in each one-hour bin, converting bytes to gigabytes by dividing by 1,073,741,824 (2^30). This captures the total volume of data downloaded per hour, which is the true signal for a bulk exfiltration scenario. The `where TotalGB > 1` then isolates hours where more than 1 GB left the storage account, aligning with the security team's threshold.

  • ✗

    StorageBlobLogs | where OperationName == 'GetBlob' | summarize avg(ResponseBodySize) by bin(TimeGenerated, 1h) | where avg_ResponseBodySize > 1073741824

    Why it's wrong here

    This is incorrect because `avg(ResponseBodySize)` measures the mean size of each individual GET, not the aggregate data transferred. A single 5 GB download mixed with hundreds of tiny reads could produce an average well below 1 GB, masking the exfiltration. Conversely, a few large operations could exceed the average threshold while the total hourly volume remains small, producing false positives. The query needs a `sum()` to reflect cumulative data movement.

  • ✗

    StorageBlobLogs | where OperationName == 'GetBlob' and ResponseBodySize > 1073741824

    Why it's wrong here

    This is incorrect because it filters for individual log entries where a single response exceeded 1 GB, so only operations that are enormous in isolation are flagged. Exfiltration is often spread across many smaller requests that collectively move gigabytes of data within an hour, and none of those individual ResponseBodySize values would pass this filter. It also lacks any temporal grouping, so it cannot evaluate the per-hour aggregate volume that the investigation requires.

  • ✗

    StorageBlobLogs | where OperationName == 'GetBlob' | summarize count() by bin(TimeGenerated, 1h) | where count_ > 1000

    Why it's wrong here

    This is incorrect because `count()` tallies the number of GetBlob operations, which is not a measure of data volume; thousands of small blob reads can happen routinely without moving a meaningful amount of data. A single operation that downloads 50 GB would trigger no alarm because it only contributes one to the count. The query should aggregate `ResponseBodySize` by summing, not count events, to detect the actual gigabytes exfiltrated per hour.

Quick reference

Azure Blob Storage Tier Comparison

TierStorage CostRetrieval CostLatencyUse Case
HotHighestLowestImmediateActive data, frequent reads
CoolLowerHigherImmediateData accessed < once / month
ColdLower stillHigherImmediateData accessed < once / quarter
ArchiveLowestHighest + rehydration delayHoursLong-term compliance retention

About these practice questions

One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.