mediumMultiple Choice
SC-200 Practice Question: A SOC analyst creates a scheduled analytics rule…
A SOC analyst creates a scheduled analytics rule in Microsoft Sentinel to detect anomalous Microsoft Entra ID sign-ins. The rule uses the SigninLogs table and runs every 15 minutes. The analyst wants to alert when a user signs in from a country that is not in the allowed list (['US', 'CA']). Which KQL query pattern should be used in the rule?
⚠ Common exam trap
It's easy for candidates to confuse the flat field name `Country` or `location` with the correct nested property `Location.countryOrRegion`, leading them to choose options that reference non-existent or incorrectly named columns.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SigninLogs | where Location.countryOrRegion !in (dynamic(['US','CA']))
The SigninLogs table stores the sign-in location in the `Location.countryOrRegion` field, which is a nested property of the `Location` dynamic object. The KQL operator `!in` with `dynamic(['US','CA'])` correctly performs a case-sensitive comparison against a list of string values, ensuring that only sign-ins from countries outside the allowed list trigger the alert.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
SigninLogs | where Location.countryOrRegion !in (dynamic(['US','CA']))
Why this is correct
The `Location` column in the SigninLogs table is a dynamic (JSON-like) object, and `Location.countryOrRegion` correctly extracts the country/region string via dot notation. The `!in` operator with a `dynamic()` array of allowed country codes excludes sign-ins from the US and CA as intended. KQL string comparisons are case-insensitive, so this filter handles variations like 'us' or 'ca' correctly. This is the only option that matches both the actual schema and Kusto syntax.
- ✗
SigninLogs | where Country !in ('US','CA')
Why it's wrong here
There is no top-level `Country` column in the SigninLogs table schema; country/region information is nested inside the dynamic `Location` field as the `countryOrRegion` property. Querying a non-existent column causes the query to fail with a semantic error because Kusto cannot resolve the column name. Even if the column existed, the scalar list would be syntactically acceptable, but the schema mismatch is the fundamental reason this query will not run.
- ✗
SigninLogs | where location != 'US' and location != 'CA'
Why it's wrong here
The lowercase `location` refers to the entire dynamic `Location` object, which is a structured JSON-like value containing multiple properties such as `countryOrRegion`, `city`, and `state`. Comparing this object directly to string literals like 'US' with `!=` will never match, because a dynamic object cannot equal a simple string; consequently, the filter evaluates to true for every row and returns all sign-ins, including those from the US and CA. This approach fails to access the nested property and thus provides no meaningful filtering.
- ✗
SigninLogs | where geoLocation !in (dynamic(['US','CA']))
Why it's wrong here
The SigninLogs table does not contain a column named `geoLocation`; the geographic information is stored in the `Location` dynamic object. Referencing `geoLocation` will immediately produce a schema error because Kusto cannot find that column. Even if the column name were corrected to `Location`, you would still need to access the nested property—e.g., `Location.countryOrRegion`—rather than compare the entire dynamic object to scalar values, so this query is invalid for two separate reasons.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.