mediumMultiple Choice
SC-200 Practice Question: Ingests Windows Security Events into Microsoft…
An organization ingests Windows Security Events into Microsoft Sentinel via the Security Events connector. An analyst wants to create a scheduled analytics rule that alerts when more than 10 failed logon events (Event ID 4625) occur for the same user within a 5-minute window. Which KQL operator should the analyst use to count events per user in that time window?
⚠ Common exam trap
A common mix-up: candidates confuse `summarize` with `extend` or `project`, mistakenly thinking that adding a calculated column or selecting columns can perform grouping and counting, when only `summarize` provides aggregation capabilities.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
summarize
The `summarize` operator is correct because it groups events by user and then applies an aggregation function (like `count()`) to calculate the number of failed logon events per user within the 5-minute window. This directly supports the rule's requirement to count events per user and compare the count to a threshold of 10.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
summarize
Why this is correct
summarize is the KQL operator that groups rows by one or more key expressions, such as User and bin(TimeGenerated, 1h), and then computes aggregate values over each group with functions like count(), dcount(), or sum(). It returns exactly one output row per unique combination of grouping keys, which reduces the event-level rows into the desired per-user, per-time-bin statistics. Using summarize count() by User, bin(TimeGenerated, 1h) on the Windows security events table directly answers this requirement, so summarize is the correct choice.
- ✗
extend
Why it's wrong here
extend creates a new column or overwrites an existing column by evaluating an expression row-by-row, leaving the table's row count unchanged. It is purely an additive, row-wise transformation and cannot collapse multiple events into group totals or compute aggregate functions such as count(). While extend could add a column like TimeBin = bin(TimeGenerated, 1h), it would still need summarize afterwards to determine how many events fell into each User and TimeBin group.
- ✗
project
Why it's wrong here
project is a schema-shaping operator that selects, renames, reorders, or drops columns from the input table while preserving the number of rows. It cannot group rows, apply aggregate functions, or produce a total per user and time interval, because it never combines or reduces rows. Project would only be useful later in the query, e.g., project User, EventCount, to keep the final results tidy after summarize has already computed the counts.
- ✗
where
Why it's wrong here
where filters each incoming row against a Boolean predicate, as in where EventID == 4625, and passes through only the rows that evaluate to true. It is a row-wise filtering operator, not a grouping or aggregation operator, so it cannot summarize counts across users or apply bin() to produce time buckets. In this scenario, where may narrow the events to relevant security IDs, but the per-user, per-time-interval counts must still be produced by a subsequent summarize.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.