SC-100 Practice Question: Design security operations, identity, and compliance capabilities
Exhibit
Refer to the exhibit. ```kusto SecurityAlert | where TimeGenerated > ago(7d) | where Severity == "High" | summarize AlertCount = count() by AlertName, CompromisedEntity | where AlertCount > 5 | project AlertName, CompromisedEntity, AlertCount ```
Refer to the exhibit. You run this KQL query in Microsoft Sentinel. What is the primary purpose?
⚠ Common exam trap
Candidates may overlook that `make_set` counts distinct alert names, not total alerts, and may also confuse the filter direction (`>5` vs `<5`), leading them to pick D. In reality, C is correct because a high number of distinct alert types indicates repeated targeting.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Detect entities that have been repeatedly targeted by high-severity alerts
The KQL query uses `make_set` to aggregate distinct high-severity alert names per entity and filters for entities with more than 5 distinct alert types. This identifies entities that have been targeted by a high variety of high-severity alerts, indicating repeated or broad attack activity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Correlate alerts across different data sources
Why it's wrong here
This query operates exclusively on the SecurityAlert table, applying a Severity filter, grouping by CompromisedEntity, and counting alerts. There are no join, union, or lookup operators that would combine SecurityAlert with other tables such as SecurityEvent, SigninLogs, or CommonSecurityLog. Therefore, it cannot correlate alerts across different data sources; it only aggregates records already present in a single table.
- ✗
Identify new high-severity alerts in the last 7 days
Why it's wrong here
The query contains no time-based filter such as `TimeGenerated > ago(7d)` or `StartTime`/`EndTime` parameters, so it does not limit results to alerts generated in the last 7 days. Instead, it aggregates all historical high-severity alerts in the table, and the `AlertCount > 5` condition specifically targets high-frequency occurrences rather than recently created alerts. The intent is to surface repeatedly targeted entities, not to isolate new or novel alerts.
- ✓
Detect entities that have been repeatedly targeted by high-severity alerts
Why this is correct
The query groups high-severity alerts by CompromisedEntity and then filters the resulting aggregation to retain only entities with an `AlertCount > 5`. This directly identifies entities—such as users, hosts, or accounts—that have been hit by more than five high-severity alerts, indicating a pattern of repeated targeting. The `summarize` operation plus the having clause on the aggregated count is classic for detecting brute-force or persistent attack victims.
- ✗
Find entities with fewer than 5 high-severity alerts
Why it's wrong here
This option misstates the direction of the filter. The query uses `where AlertCount > 5`, which selects entities with more than five high-severity alerts, not fewer. If the author wanted entities with fewer than five alerts, they would have written `AlertCount < 5`; as written, the query excludes those low-count entities entirely. Additionally, the grouping and filtering logic is about repeated targeting, not about scarcity of alerts.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.