mediumMultiple Choice
SC-200 Practice Question: Ingests its Palo Alto firewall logs into a custom…
An organization ingests its Palo Alto firewall logs into a custom table named 'PaloAlto_CL' in Microsoft Sentinel. A security analyst wants to create a scheduled analytics rule that triggers an incident when a single source IP is involved in more than 100 outbound connections to different destinations in 1 minute. Which KQL query and configuration would trigger the alert correctly?
⚠ Common exam trap
Watch out — candidates often confuse `count()` (total events) with `dcount()` (distinct values), leading candidates to select Option A, which would trigger on repeated connections to the same destination rather than the specified condition of different destinations.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
summarize dcount(DestinationIP) by SourceIP, bin(TimeGenerated,1m) and set threshold >100
The requirement is to count distinct destination IPs per source IP per minute, not total connections. Using `dcount(DestinationIP)` with `bin(TimeGenerated,1m)` ensures we count unique destinations, and setting the threshold to >100 triggers when a single source IP connects to more than 100 different destinations in one minute, exactly matching the alert condition.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
summarize count() by SourceIP, bin(TimeGenerated,1m) and set threshold >100
Why it's wrong here
This variant counts every firewall log event, not unique destinations. Because the aggregation is only by SourceIP and minute, repeated connections to the same destination IP each increment the count, so a host making 101 retries to a single server would pass a threshold of 100 even though it only contacted one distinct destination. That makes it a poor detector for the stated requirement, which specifically demands more than 100 different DestinationIP values within a minute.
- ✓
summarize dcount(DestinationIP) by SourceIP, bin(TimeGenerated,1m) and set threshold >100
Why this is correct
Using dcount(DestinationIP) is the correct measure because it approximates the number of unique destination IP addresses contacted by each source in each one-minute window. Grouping by SourceIP and bin(TimeGenerated,1m) isolates per-source scanning bursts, and threshold >100 accurately flags a single host that attempts more than 100 distinct destinations in a minute, which is the classic signature of network scanning or worm propagation. The dcount operator uses HyperLogLog estimation, which is memory-efficient and sufficiently precise for alerting at this scale.
- ✗
summarize count() by DestinationIP and threshold >100
Why it's wrong here
This query aggregates over all time and all sources, removing the two dimensions that define the detection scenario. Summing all connections to each DestinationIP ignores SourceIP entirely, so a single destination can breach 100 connections from hundreds of different clients or from one client over days, neither of which represents one source enumerating many destinations in a short burst. Without bin(TimeGenerated,1m), there is also no temporal window, so slow distributed connection rates would be incorrectly treated as an attack.
- ✗
summarize dcount(SourceIP) by DestinationIP, bin(TimeGenerated,1m) and threshold >100
Why it's wrong here
Reversing the grouping changes the question completely: here you are counting distinct SourceIP values that hit each DestinationIP in a minute. A threshold above 100 would indicate a single destination receiving connections from more than 100 distinct sources, which is a distributed denial-of-service pattern, not a single source scanning many destinations. The original requirement needs the source as the grouping dimension and the destination as the counted entity, so this variant is inverted and would both miss the intended behavior and generate different false positives.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.