Courseiva

AZ-500 Practice Question: Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel

Your security team receives a high-priority alert from Microsoft Sentinel indicating a potential brute-force attack against an Azure SQL Database. The alert was generated by an analytics rule using the following KQL query: 'SigninLogs | where ResultType == "50057" | summarize Count = count() by UserPrincipalName, IPAddress | where Count > 10'. What is the most likely cause of the alert?

⚠ Common exam trap

Watch out — candidates often confuse ResultType '50057' with generic sign-in failures or MFA errors, but Microsoft specifically uses unique error codes for each failure type, and this question tests your ability to map the code to the exact condition.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Multiple sign-in attempts using a disabled account from the same IP address.

The KQL query filters for ResultType == '50057', which specifically indicates 'User Account is Disabled'. The query then counts sign-in attempts by UserPrincipalName and IPAddress, triggering the alert when the count exceeds 10. This means the alert fires when there are more than 10 sign-in attempts from the same user and IP address against a disabled account, which matches the description of a brute-force attack targeting a disabled account.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Multiple failed MFA attempts by a user.

    Why it's wrong here

    Repeated MFA failures, such as error codes 50074 (strong auth required) or 50076 (MFA challenge failed), are common when users mistype a code or accidentally decline a prompt. These failures do not prove an attacker is attempting to compromise the account, and Microsoft's adaptive MFA policies are already designed to handle transient errors. Without additional context, such as the account being disabled or a known bad IP, this pattern is not necessarily high-priority.

  • ✗

    A user successfully signed in after many attempts.

    Why it's wrong here

    A successful sign-in with ResultType 0 indicates the user supplied valid credentials and passed MFA, so the account is in a healthy state. Even if many prior attempts occurred, the eventual success could simply mean the user finally entered the correct password after several typos, or reset their password and retried. This scenario is less suspicious than sign-in attempts against an account that is disabled, because a disabled account cannot legitimately sign in, whereas a valid user's success is expected behavior.

  • ✓

    Multiple sign-in attempts using a disabled account from the same IP address.

    Why this is correct

    Sign-in attempts against a disabled account return error code 50057 (user account disabled), which means the directory explicitly prohibits authentication. When multiple such attempts come from the same IP address, it signals a coordinated credential-stuffing or brute-force effort targeting a specific disabled account. Because a disabled account has no legitimate use, every attempt is unequivocally anomalous and represents a high-priority threat, especially if the IP shows other malicious activity.

  • ✗

    Multiple sign-in attempts from a non-existent user account.

    Why it's wrong here

    Attempts from a non-existent user return error codes like 50034 (user does not exist), and these are routine in automated directory enumeration or password-spray campaigns. Since the account does not exist, there is no resource to compromise, so the risk is limited to reconnaissance noise. This pattern is often low-priority and is typically filtered out or de-prioritized by detection rules, unlike attacks against disabled accounts where an actual account state is being targeted.

About these practice questions

One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.