Courseiva
Perform threat hunting →hardMultiple Choice

SC-200 Perform threat hunting Practice Question

Exhibit

Refer to the exhibit.
```kusto
let threshold = 10;
IdentityLogonEvents
| where Timestamp > ago(7d)
| where Application == "Microsoft Entra ID"
| summarize FailedAttempts = countif(LogonType != "Success") by AccountUpn, IPAddress
| where FailedAttempts > threshold
| join kind=inner (IdentityLogonEvents
    | where Timestamp > ago(7d)
    | where Application == "Microsoft Entra ID" and LogonType == "Success"
    | summarize SuccessfulLogons = count() by AccountUpn, IPAddress)
    on AccountUpn, IPAddress
| project AccountUpn, IPAddress, FailedAttempts, SuccessfulLogons
```

An analyst uses this KQL query in Microsoft Sentinel to hunt for potential brute-force attacks. What is the primary purpose of the join operation?

⚠ Common exam trap

SC-200 often tests KQL join semantics and detection logic, and the trap is misreading the join as a simple filter or deduplication when it is actually correlating two event sets to identify accounts with both failed and successful logons from the same IP.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

To identify accounts that had both a high number of failed logons and at least one successful logon from the same IP

The join in the KQL query correlates failed logon events with successful logon events on the same account and IP, so its primary purpose is to surface accounts that experienced many failed logons followed by at least one success from the same IP — a classic brute-force success indicator. This narrows the hunt to high-risk accounts rather than all failed logons.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    To filter out IP addresses that have only successful logons

    Why it's wrong here

    This is incorrect because an inner join does not filter out IP addresses that have only successful logons; rather, it simply ignores them because they fail to match any failed-logon row. The join is not an anti-join or exclusion operator—it correlates events, and IPs that appear solely in the successful logon table are left out as a byproduct of the matching logic. To explicitly filter out such IPs, an analyst would use the `where` operator with `not in` or a `leftanti` join.

  • ✓

    To identify accounts that had both a high number of failed logons and at least one successful logon from the same IP

    Why this is correct

    This is correct. The query first aggregates failed logon events by account and IP, then performs an inner join with successful logon events on the same account/IP pair. The inner join ensures that any matched row has at least one successful logon from that IP, while the aggregate count shows a high number of failures. Together these filters reveal accounts that suffered many failed logon attempts and ultimately had a successful logon from the same source IP—a classic indicator of a successful brute-force attack.

  • ✗

    To calculate the ratio of failed to successful logons for each account

    Why it's wrong here

    This is incorrect because a join operation does not perform arithmetic calculations. To calculate a ratio of failed to successful logons, the analyst would need to separately summarize failed and successful counts per account (or per account/IP) and then compute a division expression, such as `FailedCount * 1.0 / SuccessfulCount`. The join shown here merely merges rows that share an account and IP key, correlating events rather than producing any derived metric.

  • ✗

    To remove duplicate entries of account and IP combinations

    Why it's wrong here

    This is incorrect because a join does not deduplicate rows; in fact, joining on account and IP without prior aggregation can create a Cartesian product when an account has multiple successful logons, multiplying output rows. Removing duplicate account/IP combinations would require an operator like `summarize` with `dcount` or `distinct`, or a `summarize count() by Account, IP` followed by a filter on `count_ > 1`. The query's purpose is to correlate failed and successful events, not to clean data.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SC-200

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. During a threat hunt, a security analyst uses Microsoft Sentinel and identifies a series of failed logon attempts from a single IP address targeting multiple user accounts. The analyst wants to create a scheduled analytics rule that generates an alert when the same IP address fails to logon to more than 10 different accounts within 5 minutes. Which KQL operator should be used to count distinct accounts per IP?

medium
  • A.count()
  • B.summarize count() by Account
  • C.distinct Account
  • ✓ D.dcount(Account)

Why D: The dcount(Account) operator is correct because it counts the number of distinct values in the Account column, which is exactly what the analyst needs: the number of unique accounts targeted by failed logons from a single IP. The full query would use summarize dcount(Account) by IPAddress and then filter for counts greater than 10 within a 5-minute window. This directly addresses the requirement to count distinct accounts per IP.

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.