SC-200 Perform threat hunting Practice Question
A security analyst is using KQL in Microsoft Sentinel to hunt for potential data exfiltration by a user who has been sending unusually large amounts of data to an external IP address. Which KQL operator should the analyst use to identify the top source IP addresses and total bytes sent over the last 7 days?
⚠ Common exam trap
SC-200 often tests whether candidates confuse `count()` with `sum()` in `summarize`, or use `project`/`sort` on raw rows instead of aggregating first — the exam wants the aggregation-then-rank pattern.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
... | summarize TotalBytes=sum(SentBytes) by SourceIP | top 10 by TotalBytes desc
To identify the top source IPs by total bytes sent over 7 days, the analyst needs to aggregate bytes per source IP and then rank them. `summarize TotalBytes=sum(SentBytes) by SourceIP | top 10 by TotalBytes desc` does exactly that: it sums SentBytes grouped by SourceIP and returns the top 10 by total bytes, which is the correct KQL pattern for this hunt.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
... | where SentBytes > 1000000 | project SourceIP, SentBytes
Why it's wrong here
This query first filters the dataset to only include individual network sessions where SentBytes exceeds 1,000,000 bytes, then projects only the SourceIP and SentBytes columns. Because it never groups by SourceIP or aggregates the byte values, it cannot produce a ranked set of source IPs by total outbound volume. A source IP with many moderate-sized transfers (e.g., 500 KB each) would be completely omitted even though its total is far larger than a one-time 1 MB transfer. The result is a row-level list of large individual flows, not a summarization of per-IP totals.
- ✗
... | extend TotalBytes=SentBytes | summarize count() by SourceIP
Why it's wrong here
This query adds a new column TotalBytes that is simply a copy of the existing SentBytes value, then uses the summarize operator with count() grouped by SourceIP. The count() function counts the number of events (rows) that fall into each SourceIP bucket, not the sum of the TotalBytes or SentBytes values. As a result, a host generating thousands of low-volume connections would rank higher than a host sending a few massive transfers, even if the latter transferred far more data overall. To achieve the intended outcome, you would need to replace count() with sum(TotalBytes) or sum(SentBytes).
- ✗
... | project SourceIP, SentBytes | sort by SentBytes desc
Why it's wrong here
Here the query projects only the SourceIP and SentBytes columns for every event and then sorts all rows in descending order by the SentBytes value of each individual session. This operation does not aggregate data by SourceIP, so the same IP address may appear on many different rows, and the output shows the single largest separate network transfers, not the total bytes per IP. Without a summarize step to group and sum by SourceIP, the top of the sorted list could be dominated by many flows from the same IP or by a few huge flows from different IPs, making it impossible to answer the hunt question accurately. Additionally, the query lacks a final take or top operator, so it returns the entire sorted dataset rather than only the top 10 source IPs.
- ✓
... | summarize TotalBytes=sum(SentBytes) by SourceIP | top 10 by TotalBytes desc
Why this is correct
This is the correct approach because the summarize operator groups all events by SourceIP and calculates TotalBytes as the sum of SentBytes for each group, converting row-level byte counts into a single aggregate metric per unique IP address. The subsequent top 10 by TotalBytes desc operator then sorts those aggregated results in descending order and returns only the first ten rows, which are the ten source IPs with the highest total outbound byte volume. Using 'top' after 'summarize' is also more efficient than 'sort' followed by 'take' because Kusto can discard non-top records during execution. This pipeline precisely satisfies the goal of identifying the top source IPs by total bytes sent and is the only option that combines both grouping and aggregation with a limiting operation.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.