easyMultiple Choice
SC-200 Practice Question: A security analyst in Microsoft Sentinel wants to…
A security analyst in Microsoft Sentinel wants to create a custom analytics rule that triggers when more than 10 failed logon attempts from a single source IP address occur within 5 minutes. The analyst writes a KQL query to aggregate sign-in logs. Which KQL operator should the analyst use to group events by source IP and count each failure?
⚠ Common exam trap
Test-takers frequently confuse `extend` or `project` with aggregation, thinking they can count events by adding a column, but only `summarize` performs the required grouping and counting operation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
summarize
The `summarize` operator is correct because it groups rows by a specified key (source IP) and applies an aggregation function (like `count()`) to produce a single output row per group. In this scenario, the analyst needs to count failed logon attempts per source IP, which requires grouping and counting—exactly what `summarize` does.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
extend
Why it's wrong here
The extend operator is used to add a new calculated column to every row in the input table, typically by referencing existing columns with arithmetic or string expressions. It creates additional data at the row level but does not collapse rows or evaluate data across multiple rows. In a scenario where the analyst needs to count events, extend cannot perform the aggregation because it retains the original row count and simply enriches each row with computed values, making it an auxiliary step rather than the main grouping operator.
- ✗
project
Why it's wrong here
The project operator shapes the output by selecting a specific subset of columns, renaming them, or creating new columns through expressions, but it operates individually on each row and does not change the number of rows. It is essentially a columnar selection that lets you control the result schema, yet it has no capability to group records or calculate aggregate metrics like count(). For a query that needs to count events by some dimension, project alone would return all individual rows, failing to produce the summarized answer the analyst is after.
- ✓
summarize
Why this is correct
The summarize operator is the core aggregation mechanism in Kusto Query Language, grouping rows by one or more key columns and applying an aggregate function such as count(), sum(), or dcount() to each group, returning a single row per unique combination of those keys. In a Microsoft Sentinel context, using summarize with count() is the direct way to produce event counts by entity, user, or time interval, especially when combined with the bin() function for time-bucketed counts. This operator is functionally equivalent to SQL's GROUP BY and is indispensable for creating security analytics that require totals, averages, or distinct counts across segmented data.
- ✗
where
Why it's wrong here
The where operator filters the input table to rows that satisfy a given boolean condition, such as EventID == 4625 or Severity == 'high', effectively reducing the dataset horizontally while preserving all original columns. It is a predicate-based row filter that can narrow down the events to the ones of interest, but it neither groups rows nor computes a count; the output row count is simply the number of matching rows. In a counting query, where is usually placed before summarize to exclude irrelevant events, but it cannot replace summarize for the actual grouping and counting operation.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.