Courseiva
easyMultiple Choice

SC-200 Practice Question: A security analyst in Microsoft Sentinel wants to…

A security analyst in Microsoft Sentinel wants to create a custom analytics rule that triggers when more than 10 failed logon attempts from a single source IP address occur within 5 minutes. The analyst writes a KQL query to aggregate sign-in logs. Which KQL operator should the analyst use to group events by source IP and count each failure?

⚠ Common exam trap

Test-takers frequently confuse `extend` or `project` with aggregation, thinking they can count events by adding a column, but only `summarize` performs the required grouping and counting operation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

summarize

The `summarize` operator is correct because it groups rows by a specified key (source IP) and applies an aggregation function (like `count()`) to produce a single output row per group. In this scenario, the analyst needs to count failed logon attempts per source IP, which requires grouping and counting—exactly what `summarize` does.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    extend

    Why it's wrong here

    The extend operator is used to add a new calculated column to every row in the input table, typically by referencing existing columns with arithmetic or string expressions. It creates additional data at the row level but does not collapse rows or evaluate data across multiple rows. In a scenario where the analyst needs to count events, extend cannot perform the aggregation because it retains the original row count and simply enriches each row with computed values, making it an auxiliary step rather than the main grouping operator.

  • ✗

    project

    Why it's wrong here

    The project operator shapes the output by selecting a specific subset of columns, renaming them, or creating new columns through expressions, but it operates individually on each row and does not change the number of rows. It is essentially a columnar selection that lets you control the result schema, yet it has no capability to group records or calculate aggregate metrics like count(). For a query that needs to count events by some dimension, project alone would return all individual rows, failing to produce the summarized answer the analyst is after.

  • ✓

    summarize

    Why this is correct

    The summarize operator is the core aggregation mechanism in Kusto Query Language, grouping rows by one or more key columns and applying an aggregate function such as count(), sum(), or dcount() to each group, returning a single row per unique combination of those keys. In a Microsoft Sentinel context, using summarize with count() is the direct way to produce event counts by entity, user, or time interval, especially when combined with the bin() function for time-bucketed counts. This operator is functionally equivalent to SQL's GROUP BY and is indispensable for creating security analytics that require totals, averages, or distinct counts across segmented data.

  • ✗

    where

    Why it's wrong here

    The where operator filters the input table to rows that satisfy a given boolean condition, such as EventID == 4625 or Severity == 'high', effectively reducing the dataset horizontally while preserving all original columns. It is a predicate-based row filter that can narrow down the events to the ones of interest, but it neither groups rows nor computes a count; the output row count is simply the number of matching rows. In a counting query, where is usually placed before summarize to exclude irrelevant events, but it cannot replace summarize for the actual grouping and counting operation.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.