Refer to the exhibit. You run this KQL query in Microsoft Sentinel. What is the purpose of the query?
The query filters SecurityAlert records to the last seven days using the TimeGenerated field and then uses summarize to count rows grouped by AlertSeverity, returning one row per severity value with a count. This directly answers how many low, medium, high, and informational alerts occurred in that window. It is the intended purpose of this KQL statement.
Why this answer
The KQL query uses the `SecurityAlert` table and summarizes alerts by `AlertSeverity` using the `count()` aggregation function. The `where TimeGenerated > ago(7d)` filter restricts results to the last 7 days, and the `project` clause outputs only the severity and count columns. This directly produces a count of alerts grouped by severity over the last week, matching option B.
Exam trap
The SC-200 exam often tests the distinction between the `SecurityAlert` table (alerts) and the `SecurityIncident` table (incidents), and candidates mistakenly interpret any time-filtered count query as 'listing incidents' or 'finding the most recent alert' without recognizing the aggregation and projection logic.
How to eliminate wrong answers
Option A is wrong because the query queries the `SecurityAlert` table (alerts), not the `SecurityIncident` table (incidents), and it counts alerts rather than listing incidents. Option C is wrong because the query summarizes counts by severity, not filtering for the single most recent high-severity alert; there is no `top 1` or `sort by TimeGenerated` to isolate the latest alert. Option D is wrong because hunting results are stored in the `HuntingBookmark` table or generated via custom hunting queries, not the `SecurityAlert` table, and the query performs a simple aggregation, not a hunting operation.