Courseiva
mediumMultiple Choice

SC-200 KQL summarize operator Practice Question

A SOC analyst creates a scheduled analytics rule in Microsoft Sentinel with the following KQL query: SigninLogs | where TimeGenerated > ago(1h) | summarize StartTime = min(TimeGenerated), EndTime = max(TimeGenerated) by UserPrincipalName, IPAddress | where EndTime - StartTime < 5m and count_IPAddress > 1 The intended purpose is to detect users logging in from multiple IP addresses in a short time (impossible travel). However, the rule does not generate any alerts. What is the most likely cause?

⚠ Common exam trap

The trap here is that candidates may focus on the logic of impossible travel detection (e.g., time range, distinct IPs) and overlook the simple syntax error of referencing a column that was never created by the `summarize` operator.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The query references a column 'count_IPAddress' that does not exist. The summarize operator does not create a column with that name.

The query uses `summarize ... by UserPrincipalName, IPAddress` which groups by both fields, so it does not create a column named `count_IPAddress`. The `where` clause then references `count_IPAddress`, which does not exist, causing the query to fail silently or return no results. This is why no alerts are generated.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The query references a column 'count_IPAddress' that does not exist. The summarize operator does not create a column with that name.

    Why this is correct

    The `summarize` operator groups by `UserPrincipalName` and `IPAddress`, producing one row per pair; it never emits a `count_IPAddress` column. Referencing that non-existent column causes the query to fail, so the scheduled rule returns no results and raises no alerts, satisfying the stem's "no alerts" constraint.

  • ✗

    The query does not filter for failed sign-ins (e.g., ResultType == 0).

    Why it's wrong here

    The query may also need to filter for success or failure, but the primary reason for no alerts is the missing column, not the lack of a filter.

  • ✗

    The rule should use a longer time range, such as 24 hours.

    Why it's wrong here

    The time range of 1 hour is already longer than the 5-minute window; the issue is not the time range but the incorrect column reference.

  • ✗

    The rule needs to use the 'make_set' function to correctly count distinct IP addresses.

    Why it's wrong here

    While using make_set is a correct approach, the absence of that function is not the reason for the rule failing. The immediate issue is the invalid column name.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.