Courseiva

SC-100 Practice Question: Design security operations, identity, and compliance capabilities

Exhibit

SecurityEvent
| where EventID == 4625
| summarize FailureCount = count() by Account, IPAddress
| where FailureCount > 10
| project Account, IPAddress, FailureCount

Refer to the exhibit. A KQL query is used in Microsoft Sentinel to detect brute-force attacks. The query returns no results despite known brute-force attempts. What is the most likely issue?

⚠ Common exam trap

Microsoft often tests the misconception that a single EventID (like 4625) covers all authentication failures, when in reality different protocols and authentication methods generate distinct EventIDs, and candidates must consider the broader log source landscape.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The EventID 4625 may not cover all authentication failures

EventID 4625 in Windows Security logs specifically records failed logon attempts, but brute-force attacks may target other authentication protocols (e.g., RDP, SMB, or network-level authentication) that generate different EventIDs (such as 4648, 4776, or 5156). Additionally, some brute-force attempts might be blocked at the network layer or use non-Windows authentication methods, so relying solely on EventID 4625 will miss those events. Therefore, the query returns no results because it does not capture all authentication failure scenarios.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The EventID 4625 may not cover all authentication failures

    Why this is correct

    While EventID 4625 captures Windows failed logon attempts, it does not include all authentication failure scenarios, such as Kerberos pre-authentication failures (EventID 4771), credential validation failures (EventID 4776), or failures from non-Windows sources like Microsoft Entra ID sign-in logs. Additionally, certain failure conditions may generate different event IDs depending on the logon type or protocol, so a detection rule based solely on 4625 will have blind spots for those authentication failures.

  • ✗

    The query lacks a time filter

    Why it's wrong here

    A missing time filter does not invalidate the query, because analytics rules in Microsoft Sentinel apply an implicit time range defined by the rule's query scheduling and lookback period, and KQL queries executed manually against a workspace default to a 24-hour or user-defined time span. While an explicit time filter is a best practice for performance and to avoid scanning irrelevant data, its absence does not cause the query to fail or miss detections that would otherwise occur within the evaluated window.

  • ✗

    The 'IPAddress' field does not exist in SecurityEvent

    Why it's wrong here

    The assertion that IPAddress does not exist in SecurityEvent is false; the SecurityEvent table does contain an IP address column (often referenced as IpAddress or IPAddress) that stores the source IP address, and it is commonly used in KQL queries for security analytics. Even if there are case-sensitivity nuances in KQL column references, the field itself is a valid part of the schema, so this is not a reason the query would be incorrect.

  • ✗

    The 'count()' aggregation is incorrect

    Why it's wrong here

    The count() aggregation is a standard KQL aggregation function that returns the number of rows per group when used with summarize, so it is not incorrect. There is no requirement to use count_distinct or other functions unless counting unique values, and the query's use of count() after a where clause and summarize group is syntactically and semantically valid. Therefore, this option does not represent a flaw in the detection query.

About these practice questions

Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.