mediumMultiple Choice
SC-200 Practice Question: A security analyst is creating a custom detection…
A security analyst is creating a custom detection rule in Microsoft 365 Defender using Advanced Hunting. The rule should alert when a user signs in from an IP address that is not in the company's approved IP range (192.168.0.0/16). Which KQL function should be used to compare the sign-in IP against the approved range?
⚠ Common exam trap
Candidates often choose `ipv4_is_private()` thinking it covers all internal ranges, but it does not account for custom or non-RFC 1918 ranges, and it misses the requirement to match a specific CIDR block like 192.168.0.0/16.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
ipv4_is_in_range(SigninIP, '192.168.0.0/16')
The correct KQL function is `ipv4_is_in_range()` because it is specifically designed to check whether an IPv4 address falls within a given CIDR range. In this scenario, the function compares the `SigninIP` field against the company's approved range `192.168.0.0/16` and returns `true` if the IP is within that range, enabling the rule to alert on out-of-range sign-ins. This function handles subnet mask calculations natively, ensuring accurate and efficient IP range matching without manual parsing.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
ipv4_is_in_range(SigninIP, '192.168.0.0/16')
Why this is correct
The ipv4_is_in_range function parses both the IP address and the CIDR range, then performs a proper bitwise comparison of the network prefix based on the specified prefix length. It returns true only when the SigninIP falls within the exact 192.168.0.0/16 address space, correctly handling subnet boundaries. This is the recommended KQL approach for testing IP membership in a specific CIDR range and is both reliable and efficient.
- ✗
has_any(SigninIP, dynamic(['192.168.0.0/16']))
Why it's wrong here
The has_any operator checks whether the source string contains any of the specified substrings using substring matching, and it does not interpret values as network addresses. When given dynamic(['192.168.0.0/16']), it looks for the literal text '192.168.0.0/16' inside the SigninIP string, which never appears because an IP address does not include a slash or the /16 suffix. Consequently, this expression always evaluates to false (or behaves incorrectly) and completely fails to perform CIDR range evaluation.
- ✗
ipv4_is_private(SigninIP)
Why it's wrong here
The ipv4_is_private function determines whether an IP address belongs to any of the RFC1918 private address blocks: 10.0.0.0/8, 172.16.0.0/12, and 192.168.0.0/16. While 192.168.0.0/16 is one of those blocks, this function tests membership across the entire private address space, not just the specified /16 range. An IP such as 172.16.5.10 would also return true, causing the detection rule to trigger for unintentional ranges and thereby producing false positives if the intent was to monitor only 192.168.0.0/16.
- ✗
SigninIP startswith '192.168.'
Why it's wrong here
The startswith operator performs a literal string prefix comparison rather than an IP-aware network calculation. It will match any IP address whose textual representation begins with '192.168.', without understanding CIDR boundaries or subnet masks. For example, a rule intended to detect 192.168.1.0/24 would incorrectly also match 192.168.2.0/24 because the string prefix remains identical. This makes it unsuitable for precise subnet scoping in security detections.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.