Courseiva
easyMultiple Choice

SC-200 Practice Question: A SOC manager wants to quickly view the number of…

A SOC manager wants to quickly view the number of incidents generated in Microsoft Sentinel over the past 7 days, grouped by Azure subscription. Which KQL query should be used on the SecurityIncident table?

⚠ Common exam trap

Test-takers frequently confuse the SecurityIncident table's SubscriptionId with WorkspaceSubscriptionId, or using the wrong time field (TimeGenerated instead of CreatedTime), leading candidates to pick options that either query the wrong table or group by the wrong subscription identifier.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

SecurityIncident | where CreatedTime > ago(7d) | summarize count() by SubscriptionId

The SecurityIncident table stores incident records, and the CreatedTime field records when each incident was generated. Filtering with `where CreatedTime > ago(7d)` limits results to the past 7 days, and `summarize count() by SubscriptionId` groups the count by the Azure subscription that owns the resources involved in the incident. This directly meets the SOC manager's requirement to view the number of incidents per subscription over the last week.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    SecurityIncident | where CreatedTime > ago(7d) | summarize count() by SubscriptionId

    Why this is correct

    SecurityIncident is the correct table because it stores the definitive incident records that a SOC triages, and CreatedTime is the standard timestamp column indicating when an incident was generated. Filtering with ago(7d) limits results to the last seven days, while summarize count() by SubscriptionId groups the incidents by the Azure subscription containing the affected resources, directly satisfying the manager's request to see incident counts per subscription.

  • ✗

    SecurityAlert | where TimeGenerated > ago(7d) | summarize count() by SubscriptionId

    Why it's wrong here

    The SecurityAlert table contains individual raw alerts generated by detection engines, not the incidents formed after correlation and deduplication. Querying it would return alert counts, which are typically many-to-one with incidents, so the numbers would be inflated and misleading. Even though TimeGenerated is the correct timestamp column for alerts, the wrong table makes this query invalid for counting incidents.

  • ✗

    SecurityIncident | where TimeGenerated > ago(7d) | summarize count() by SubscriptionId

    Why it's wrong here

    Although SecurityIncident is the right table, this query filters on TimeGenerated, a column that does not exist in the schema. The valid timestamp columns in SecurityIncident are CreatedTime and ModifiedTime, so the query would throw a schema error or return zero records. Referencing a nonexistent column prevents the query from executing correctly, making it technically wrong despite the intended logic.

  • ✗

    SecurityIncident | where CreatedTime > ago(7d) | summarize count() by WorkspaceSubscriptionId

    Why it's wrong here

    WorkspaceSubscriptionId represents the subscription that hosts the Log Analytics workspace, not the subscription of the resources involved in the incident. In a centralized workspace that ingests logs from multiple subscriptions, grouping by this field would aggregate all incidents into the workspace's own subscription and hide the true resource-subscription breakdown. The correct field is SubscriptionId, which captures the subscription of the affected resource and provides the per-subscription counts the manager expects.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.