Courseiva
hardMultiple Choice

SC-200 Practice Question: A KQL query detects brute-force attempts by…

A KQL query detects brute-force attempts by summarizing failed sign-ins by user, IP address, and five-minute time bins. Which operator is most appropriate for this aggregation?

⚠ Common exam trap

Many candidates confuse `extend` with `summarize` because both can create new columns, but only `summarize` performs grouping and aggregation, which is essential for detecting brute-force patterns over time bins.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

summarize.

The `summarize` operator is the correct choice because it groups rows by specified columns (user, IP address, and five-minute time bins) and applies an aggregation function (e.g., `count()`) to detect brute-force patterns. In KQL, `summarize` is the only operator that can create time-binned aggregations using the `bin()` function, which is essential for grouping failed sign-ins into fixed five-minute intervals. This directly supports the brute-force detection requirement by counting failed attempts per user/IP/time window.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    summarize.

    Why this is correct

    In Kusto Query Language, the summarize operator is the core aggregation operator, as it groups rows by specified key columns and computes aggregate functions such as count(), dcount(), or make_set(). For detecting brute-force attacks, summarize is used to count failed authentication attempts per distinct user, source IP, and a time bucket like bin(TimeGenerated, 5m). This grouping produces a summary table where each row represents a unique combination of these dimensions, allowing analysts to spot spikes in failed attempts that exceed a threshold and trigger an investigation. No other operator in this list can produce the required counts and groupings.

  • ✗

    project-away.

    Why it's wrong here

    project-away is a projection operator that simply removes one or more columns from the input table, leaving the row count unchanged. For example, project-away Date, IP would drop fields, but it would not combine or count events, so it cannot identify brute-force patterns. While cleaning irrelevant fields could be part of a larger query, the actual brute-force detection must rely on summarize to aggregate failures. Because brute-force detection inherently requires reducing many log rows into a manageable set of statistics, project-away alone is insufficient.

  • ✗

    parse_json.

    Why it's wrong here

    parse_json is a scalar function that converts a string containing JSON text into a dynamic object for further field access or manipulation, such as extracting a nested property. It operates on a row-by-row basis and does not group, aggregate, or count events, so it cannot reveal how many sign-in failures occurred per IP or user. In brute-force queries, parse_json might be used to parse a 'Details' column containing JSON, but it would never by itself produce the summarized counts needed to flag an attack. Its role, if any, is data transformation, not aggregation.

  • ✗

    extend.

    Why it's wrong here

    extend creates, or modifies, one or more calculated columns based on existing columns, but it does not change the granularity of the data—each row remains a distinct event. You might use extend to add a conditional flag like Failed = (ResultType == 'Fail'), yet you still must feed that flag into a summarize operator to count true values. Without summarize, extend leaves every sign-in attempt as its own row, making it impossible to view a high-level pattern of brute-force activity over time. Thus, extend is a tabular operator for enrichment, not for aggregation.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.