Courseiva

SC-200 Respond to security incidents Practice Question

A SOC analyst is using Microsoft Sentinel to investigate an incident involving a user who accessed a sensitive database from an unusual location. The analyst wants to find all activities performed by this user within the last 24 hours from multiple data sources. Which KQL operator should the analyst use to combine the results of two queries that return different schemas?

⚠ Common exam trap

SC-200 often tests the difference between union (append, different schemas) and join (match, same key columns), causing candidates to pick join when the question explicitly says 'different schemas'.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

union

The union operator in KQL combines the results of two or more queries that may have different schemas, appending rows and filling missing columns with nulls. This is exactly what the analyst needs to pull user activity from multiple data sources (e.g., SigninLogs, AuditLogs, OfficeActivity) into a single result set for the last 24 hours. join, by contrast, requires matching columns and merges rows horizontally.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    summarize

    Why it's wrong here

    The KQL `summarize` operator aggregates rows into grouped summary statistics such as count(), sum(), avg(), min(), max(), dcount(), or make_set(). Its purpose is to reduce the cardinality of a single table by grouping on dimensions, not to merge separate result sets. In an incident investigation requiring you to combine evidence from different data sources with distinct schemas, `summarize` would collapse or discard row-level detail and cannot bring disparate columns together into a unified result set, so it is incorrect.

  • ✗

    join

    Why it's wrong here

    The KQL `join` operator merges rows from two tables horizontally by matching rows on one or more common fields, producing a wide output that contains columns from both inputs. This requires meaningful shared keys and often causes column-name collisions and row multiplication when schemas or relationships are not cleanly defined. It cannot combine multiple tables with different schemas in a simple side-by-side way if the investigation simply needs all available events stacked together, so it is not the right operator for combining heterogeneous result sets.

  • ✓

    union

    Why this is correct

    The KQL `union` operator is the correct choice because it appends rows from two or more tables vertically into a single result set. If the tables have different columns, `union` returns all distinct columns and fills missing values with nulls, which is exactly what is needed to consolidate security data from various sources like SigninLogs, SecurityEvent, and AzureActivity. In Sentinel hunting queries, `union` allows an analyst to stack data sources with different schemas without losing any columns and is standard for cross-source investigation.

  • ✗

    where

    Why it's wrong here

    The KQL `where` operator filters rows in a single tabular result by applying a Boolean predicate to column values. It does not combine, merge, or append multiple data tables or query results; it only restricts which rows from an already-existing table are returned. Using `where` after a lookup or on one table cannot bring in records from other sources, so it is fundamentally incapable of producing the combined result set needed for this investigation.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.