Courseiva
easyMultiple Choice

SC-200 Practice Question: A SOC analyst wants to create a scheduled…

A SOC analyst wants to create a scheduled analytics rule in Microsoft Sentinel that runs every hour and detects multiple failed user login attempts from a single IP address within a 5-minute window. Which KQL function should be used in the query to group the failed events by 5-minute time intervals?

⚠ Common exam trap

It's easy for candidates to confuse the `bin()` function with simple grouping by timestamp (Option B) or mistakenly think that `datetime_diff` (Option C) can be used to group events, when in fact only `bin()` provides the correct fixed-interval bucketing required for time-windowed aggregations.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

summarize count() by IPAddress, bin(TimeGenerated, 5m)

The `bin()` function in KQL is specifically designed to group data into fixed-size time buckets, such as 5-minute intervals. By using `summarize count() by IPAddress, bin(TimeGenerated, 5m)`, the query counts failed login attempts per IP address within each 5-minute window, which directly meets the requirement for a scheduled rule that detects multiple failures from a single IP in a 5-minute period.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    summarize count() by IPAddress, bin(TimeGenerated, 5m)

    Why this is correct

    The bin(TimeGenerated, 5m) function rounds each event's timestamp down to the start of its containing five-minute interval, so summarize groups all events from the same IPAddress that occur within that same bucket and counts them as a single aggregate. This is the standard KQL pattern for time-windowed aggregation in scheduled analytics rules because it collapses many raw events into per-IP, per-window counts. Without a bin expression, the query would not define fixed time windows, making this the only option that correctly produces the desired 5-minute grouping.

  • ✗

    summarize count() by IPAddress, TimeGenerated

    Why it's wrong here

    Grouping solely by IPAddress and the exact TimeGenerated timestamp does not create a fixed five-minute window; instead, it preserves every distinct timestamp down to the second or millisecond. Because the original event timestamps are almost always unique, each group will typically contain only one row, so count() will mostly return 1 rather than summarizing activity across a five-minute span. This query therefore fails to detect a buildup of multiple events from the same IP within the intended period, which is the core purpose of a time-windowed aggregate rule.

  • ✗

    extend interval = datetime_diff('minute', TimeGenerated, ago(5m))

    Why it's wrong here

    This expression uses datetime_diff to compute, for each existing row, the minute-level difference between TimeGenerated and a point five minutes in the past (ago(5m)). That produces a scalar value on every row without any grouping or aggregation, so it never buckets events into five-minute windows and does not yield a count per IP. It also does not align to clock-based boundaries; it simply measures elapsed time on a per-event basis, making it useless for the time-window aggregation required in a scheduled analytics rule.

  • ✗

    scan with (match all events within 5m by IPAddress)

    Why it's wrong here

    The scan operator is designed for sequence recognition across ordered events—such as detecting a pattern where one event follows another—not for producing simple time-window counts per IP. Additionally, the given syntax 'scan with (match all events within 5m by IPAddress)' is not a valid representation of scan's match mode, which expects a series of state transitions rather than an aggregation key. Even conceptually, scan does not group events into 5-minute bins and return a count; it emits matched sequences, so it cannot replace summarize with bin for this analytics rule.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.