Courseiva

SC-100 Practice Question: Design security operations, identity, and compliance capabilities

Exhibit

Refer to the exhibit.
```kusto
SecurityAlert
| where TimeGenerated > ago(7d)
| where Severity == "High"
| summarize AlertCount = count() by AlertName, CompromisedEntity
| where AlertCount > 5
| project AlertName, CompromisedEntity, AlertCount
```

Refer to the exhibit. You run this KQL query in Microsoft Sentinel. What is the primary purpose?

⚠ Common exam trap

Candidates may overlook that `make_set` counts distinct alert names, not total alerts, and may also confuse the filter direction (`>5` vs `<5`), leading them to pick D. In reality, C is correct because a high number of distinct alert types indicates repeated targeting.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Detect entities that have been repeatedly targeted by high-severity alerts

The KQL query uses `make_set` to aggregate distinct high-severity alert names per entity and filters for entities with more than 5 distinct alert types. This identifies entities that have been targeted by a high variety of high-severity alerts, indicating repeated or broad attack activity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Correlate alerts across different data sources

    Why it's wrong here

    This query operates exclusively on the SecurityAlert table, applying a Severity filter, grouping by CompromisedEntity, and counting alerts. There are no join, union, or lookup operators that would combine SecurityAlert with other tables such as SecurityEvent, SigninLogs, or CommonSecurityLog. Therefore, it cannot correlate alerts across different data sources; it only aggregates records already present in a single table.

  • ✗

    Identify new high-severity alerts in the last 7 days

    Why it's wrong here

    The query contains no time-based filter such as `TimeGenerated > ago(7d)` or `StartTime`/`EndTime` parameters, so it does not limit results to alerts generated in the last 7 days. Instead, it aggregates all historical high-severity alerts in the table, and the `AlertCount > 5` condition specifically targets high-frequency occurrences rather than recently created alerts. The intent is to surface repeatedly targeted entities, not to isolate new or novel alerts.

  • ✓

    Detect entities that have been repeatedly targeted by high-severity alerts

    Why this is correct

    The query groups high-severity alerts by CompromisedEntity and then filters the resulting aggregation to retain only entities with an `AlertCount > 5`. This directly identifies entities—such as users, hosts, or accounts—that have been hit by more than five high-severity alerts, indicating a pattern of repeated targeting. The `summarize` operation plus the having clause on the aggregated count is classic for detecting brute-force or persistent attack victims.

  • ✗

    Find entities with fewer than 5 high-severity alerts

    Why it's wrong here

    This option misstates the direction of the filter. The query uses `where AlertCount > 5`, which selects entities with more than five high-severity alerts, not fewer. If the author wanted entities with fewer than five alerts, they would have written `AlertCount < 5`; as written, the query excludes those low-count entities entirely. Additionally, the grouping and filtering logic is about repeated targeting, not about scarcity of alerts.

About these practice questions

Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.