Courseiva

SC-200 Manage a security operations environment Practice Question

A security analyst reports that a scheduled analytics rule in Microsoft Sentinel has stopped generating incidents after a recent update. The rule still runs but produces no alerts. What should you check first?

⚠ Common exam trap

It's easy for candidates to assume a rule that 'still runs' is functioning correctly, but Microsoft tests the distinction between execution and result generation—a rule can execute its query yet produce zero alerts due to query logic issues, not configuration or automation problems.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Review the rule's query logic for changes or syntax errors.

The most likely cause of a scheduled analytics rule running but producing no alerts is a change or error in the KQL query logic. Since the rule still executes, the issue is not with the rule being disabled or paused, but rather with the query failing to return results due to syntax errors, schema changes, or logic flaws introduced during the update.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Verify that the rule is enabled and not paused.

    Why it's wrong here

    Because the analytics rule is still executing on its schedule, it cannot be disabled or paused; disabled rules do not run at all and have no run history. Verifying enablement/pause status therefore addresses scheduling, not the content of the query results. The absence of alerts while the rule runs points to the query returning zero matching rows, not to the rule being turned off.

  • ✗

    Check the entity mapping configuration for missing fields.

    Why it's wrong here

    Entity mappings in a scheduled analytics rule define how result fields are translated into entity types (account, host, IP) when an incident is enriched. Incorrect or missing mappings can degrade incident context, but they do not filter query results or stop alert creation. Since the problem is that no alerts are created at all, entity mapping is not a possible cause.

  • ✓

    Review the rule's query logic for changes or syntax errors.

    Why this is correct

    Scheduled analytics rules only raise an alert for each row returned by their KQL query. If the query logic was recently changed—adding an overly restrictive where clause, altering the time range, referencing a renamed table or column—or contains a syntax error, the query can return zero results or fail before producing output. That directly explains why the rule runs on schedule yet no alerts are generated, making query review the first diagnostic step.

  • ✗

    Ensure that the automation rule triggering the incident is still active.

    Why it's wrong here

    Automation rules operate after an alert exists—they can create incidents from alerts, run playbooks, or suppress responses—but they cannot generate or suppress the underlying alert. If the analytics rule is producing no alerts, checking whether incident-creation automation is active only inspects the downstream incident pipeline. The root cause is upstream in the analytics query or alert creation logic, not in automation.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.