Courseiva
Perform threat hunting →mediumMultiple Choice

SC-200 Perform threat hunting Practice Question

A security analyst is performing threat hunting in Microsoft Sentinel and wants to identify anomalous outbound network connections from a compromised workstation. The analyst suspects that a beaconing pattern is present. Which KQL function is most appropriate to detect periodic beaconing behavior over time?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

startofday(TimeGenerated)

`startofday` groups timestamps by day, enabling analysts to count events per day and identify regular intervals characteristic of beaconing (e.g., daily connections). Option A is incorrect: `series_decompose` is used for time series decomposition (trend, seasonal, residual) but is not the most direct method for detecting periodic beaconing; it is more complex and typically used after aggregation. Option B is incorrect: `make_list` creates a list of values, not useful for periodicity detection. Option D is incorrect: `bin(TimeGenerated, 1h)` bins events into hourly buckets, which could detect beaconing at finer granularity, but daily beaconing is better suited to `startofday`; `bin` is not specifically for periodic pattern detection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    series_decompose(TimeGenerated)

    Why it's wrong here

    series_decompose() is a time series analysis function that decomposes a metric into trend, seasonal, and residual components using the STL decomposition method. It is designed for anomaly detection on an already-created time series, not for discovering whether a raw timestamp column exhibits periodic behavior. In threat hunting, you would use it after you suspect a beacon interval, not as a first-line test to identify daily periodicity from TimeGenerated.

  • ✗

    make_list(TimeGenerated)

    Why it's wrong here

    make_list(TimeGenerated) aggregates all timestamps in the group into a dynamic JSON array. While this list could theoretically be processed to compute gaps or intervals, doing so requires additional functions like array_sort and range, and the raw list itself gives no immediate indication of periodicity. It is a low-level building block, not a detection technique, and it is inefficient for large event volumes because it materializes every timestamp in memory.

  • ✓

    startofday(TimeGenerated)

    Why this is correct

    startofday(TimeGenerated) truncates each timestamp to the beginning of its calendar day, so grouping by this expression counts events per day. For a host that beacons once daily, the daily event count will remain consistently near one per day, making the periodic pattern easy to spot with a simple summarize query. This directly aligns with the hypothesis of a daily beacon and is the most appropriate choice among the options for detecting periodicity in typical C2 traffic.

  • ✗

    bin(TimeGenerated, 1h)

    Why it's wrong here

    bin(TimeGenerated, 1h) groups events into fixed one-hour buckets, which might be useful for hourly patterns but is too granular for most beaconing operations. Daily beacons would be fragmented across 24 different hourly buckets, especially if the beacon time varies slightly each day, obscuring the periodicity rather than revealing it. It also creates many empty or sparse bins, adding noise to the analysis, whereas a daily grouping would consolidate the signal.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.