Courseiva
mediumMultiple Choice

SC-200 Practice Question: A SOC analyst wants to create a Microsoft…

A SOC analyst wants to create a Microsoft Sentinel scheduled analytics rule that alerts when a user from a critical department (e.g., Finance) logs on from an IP address that is not in the company's approved IP address ranges. The analyst has an Azure Sentinel watchlist named 'FinanceApprovedIPs' containing the allowed IP ranges. Which KQL operator should be used in the rule's query to efficiently check if the IP address from SigninLogs falls within any of the watchlist ranges?

⚠ Common exam trap

Test-takers frequently confuse string-based operators like `has`, `in`, or `startswith` with IP-specific functions, failing to recognize that IP range matching requires subnet-aware logic (CIDR) rather than simple text comparison.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

join kind=inner (watchlist) on $left.IPAddress $right.IPRange with condition using ipv4_is_in_range() or ipv4_lookup()

The `ipv4_lookup()` function (or `ipv4_is_in_range()` used with a join) is specifically designed to efficiently check whether an IP address falls within a range defined in a watchlist. In Microsoft Sentinel, watchlists store data as tables, and `ipv4_lookup()` performs a range-based lookup using CIDR notation, which is far more efficient than string-based or exact-match operators. This allows the query to match the `IPAddress` from `SigninLogs` against the `IPRange` column in the `FinanceApprovedIPs` watchlist without iterating over every possible address.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    join kind=inner (watchlist) on $left.IPAddress $right.IPRange with condition using ipv4_is_in_range() or ipv4_lookup()

    Why this is correct

    The join correctly pairs each sign-in event with the watchlist's range entries, then applies ipv4_is_in_range() (or ipv4_lookup()) inside the condition to evaluate whether the sign-in IP falls within the specified CIDR block or address range. This is the only pattern that performs true network-range comparison rather than string or exact-value matching. The inner join also filters to only events that have a matching range, effectively acting as an allowlist check. This approach scales well because the watchlist is loaded into memory and the function runs natively in KQL.

  • ✗

    where IPAddress has any (watchlist)

    Why it's wrong here

    The 'has' operator performs substring or token containment on string values, so it would look for the literal text of a watchlist range (e.g., '10.0.0.0/24') inside the IP address string, which is meaningless for address ranges. It does not interpret CIDR notation or start/end boundaries, so an IP like 10.0.0.5 would not match unless the exact range text appears as a substring, which it rarely does. Additionally, 'has any' expects individual values, not range definitions, so the watchlist's columns are not leveraged correctly.

  • ✗

    where IPAddress in (watchlist)

    Why it's wrong here

    The 'in' operator tests for exact equality between the IP address and each watchlist value, but watchlist entries are typically CIDR ranges (e.g., '192.168.1.0/24') or start-end pairs, neither of which will be equal to a single IP string. Even if the IP is inside the range, the string comparison fails because '10.0.0.5' does not equal '10.0.0.0/24'. Consequently, this query would return zero matches unless a watchlist row literally contains the exact IP string, which defeats the purpose of range-based allowlisting.

  • ✗

    where IPAddress startswith (watchlist)

    Why it's wrong here

    The 'startswith' operator is a string prefix match, so it would only match if the watchlist's range string begins with the exact characters of the IP address (or vice versa), which is inverted for CIDR notation—for example, the IP '10.0.1.5' does not start with '10.0.1.0/24' and the range does not start with the IP either. It completely ignores the network prefix and subnet math required for range evaluation. This operator is meant for text fields like hostnames or file paths, not for binary network comparisons.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.