Courseiva
mediumMultiple Choice

SC-200 Practice Question: A security analyst is creating a custom detection…

A security analyst is creating a custom detection rule in Microsoft 365 Defender using Advanced Hunting. The rule should alert when a user signs in from an IP address that is not in the company's approved IP range (192.168.0.0/16). Which KQL function should be used to compare the sign-in IP against the approved range?

⚠ Common exam trap

Candidates often choose `ipv4_is_private()` thinking it covers all internal ranges, but it does not account for custom or non-RFC 1918 ranges, and it misses the requirement to match a specific CIDR block like 192.168.0.0/16.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

ipv4_is_in_range(SigninIP, '192.168.0.0/16')

The correct KQL function is `ipv4_is_in_range()` because it is specifically designed to check whether an IPv4 address falls within a given CIDR range. In this scenario, the function compares the `SigninIP` field against the company's approved range `192.168.0.0/16` and returns `true` if the IP is within that range, enabling the rule to alert on out-of-range sign-ins. This function handles subnet mask calculations natively, ensuring accurate and efficient IP range matching without manual parsing.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    ipv4_is_in_range(SigninIP, '192.168.0.0/16')

    Why this is correct

    The ipv4_is_in_range function parses both the IP address and the CIDR range, then performs a proper bitwise comparison of the network prefix based on the specified prefix length. It returns true only when the SigninIP falls within the exact 192.168.0.0/16 address space, correctly handling subnet boundaries. This is the recommended KQL approach for testing IP membership in a specific CIDR range and is both reliable and efficient.

  • ✗

    has_any(SigninIP, dynamic(['192.168.0.0/16']))

    Why it's wrong here

    The has_any operator checks whether the source string contains any of the specified substrings using substring matching, and it does not interpret values as network addresses. When given dynamic(['192.168.0.0/16']), it looks for the literal text '192.168.0.0/16' inside the SigninIP string, which never appears because an IP address does not include a slash or the /16 suffix. Consequently, this expression always evaluates to false (or behaves incorrectly) and completely fails to perform CIDR range evaluation.

  • ✗

    ipv4_is_private(SigninIP)

    Why it's wrong here

    The ipv4_is_private function determines whether an IP address belongs to any of the RFC1918 private address blocks: 10.0.0.0/8, 172.16.0.0/12, and 192.168.0.0/16. While 192.168.0.0/16 is one of those blocks, this function tests membership across the entire private address space, not just the specified /16 range. An IP such as 172.16.5.10 would also return true, causing the detection rule to trigger for unintentional ranges and thereby producing false positives if the intent was to monitor only 192.168.0.0/16.

  • ✗

    SigninIP startswith '192.168.'

    Why it's wrong here

    The startswith operator performs a literal string prefix comparison rather than an IP-aware network calculation. It will match any IP address whose textual representation begins with '192.168.', without understanding CIDR boundaries or subnet masks. For example, a rule intended to detect 192.168.1.0/24 would incorrectly also match 192.168.2.0/24 because the string prefix remains identical. This makes it unsuitable for precise subnet scoping in security detections.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.