Courseiva
easyMultiple Choice

SC-200 Practice Question: A security analyst wants to quickly check the…

A security analyst wants to quickly check the number of incidents created in Microsoft Sentinel in the last 7 days, grouped by severity. Which KQL query should the analyst use?

⚠ Common exam trap

Candidates often confuse the SecurityIncident table (for incidents) with the SecurityAlert table (for alerts), as many candidates mistakenly use SecurityAlert when the question explicitly asks for incident counts.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

SecurityIncident | where TimeGenerated > ago(7d) | summarize count() by Severity

The SecurityIncident table in Microsoft Sentinel stores incident records, and the query filters for incidents created in the last 7 days using `where TimeGenerated > ago(7d)`, then groups them by severity with `summarize count() by Severity`. This directly answers the analyst's need to check the number of incidents grouped by severity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    SecurityIncident | where TimeGenerated > ago(7d) | summarize count() by Severity

    Why this is correct

    The SecurityIncident table in Microsoft Sentinel stores incident records generated by the analytics and correlation engine. By filtering on TimeGenerated > ago(7d), this KQL query limits results to incidents that were created in the past week, and the summarize count() by Severity then aggregates those incidents into buckets of Informational, Low, Medium, and High. Because the analyst specifically asked for the number of incidents, this is the correct table and aggregation.

  • ✗

    SecurityAlert | where TimeGenerated > ago(7d) | summarize count() by Severity

    Why it's wrong here

    SecurityAlert contains individual alert telemetry ingested from connected sources such as Microsoft Defender and Azure Defender, not the synthesized incident entities that appear in a Sentinel workspace. While an incident may consolidate multiple alerts, simply grouping SecurityAlert rows by Severity yields a count of alerts rather than the distinct incident count, which can inflate numbers significantly. Thus, this query fails to accurately answer the request for incident counts.

  • ✗

    SigninLogs | where TimeGenerated > ago(7d) | summarize count() by Status

    Why it's wrong here

    SigninLogs is an Microsoft Entra ID (Azure AD) table that records authentication attempts, listing properties like UserPrincipalName, AppDisplayName, and Status for sign-in success or failure. It has no relationship to Microsoft Sentinel incidents and the Status field does not correlate to an incident's severity or even existence. Using this table would return tens of thousands of sign-in events across the last seven days, not isolated security incidents.

  • ✗

    DeviceEvents | where TimeGenerated > ago(7d) | summarize count() by ActionType

    Why it's wrong here

    DeviceEvents originates from Microsoft Defender for Endpoint and tracks low-level endpoint behaviors, such as process creation, file modifications, or network connections. Its ActionType column describes the specific observable action taken on a device, like 'FileCreated' or 'ProcessCreated', and it lacks any direct linkage to Sentinel incidents. Therefore, aggregating by ActionType is meaningless for incident severity reporting, as this table holds raw telemetry rather than detection outcomes.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.