Courseiva

KQL Join Missing Time Window — Detection Rule Debugging

Exhibit

Refer to the exhibit.

```kusto
DeviceProcessEvents
| where Timestamp > ago(7d)
| where FileName in~ ("powershell.exe", "cmd.exe")
| extend ParentPID = InitiatingProcessParentFileName
| summarize Count = count() by DeviceName, InitiatingProcessFileName
| where Count > 10
```

Refer to the exhibit. You are analyzing a KQL query used in a custom detection rule in Microsoft Defender XDR. The rule is supposed to detect devices where a parent process launched more than 10 instances of PowerShell or cmd.exe in the last 7 days. However, the query returns no results even though you know such activity exists. What is the most likely reason?

⚠ Common exam trap

Candidates often assume the column name 'ParentProcessFileName' is correct based on intuition or generic naming conventions, without verifying the actual schema of the DeviceProcessEvents table in Microsoft Defender XDR.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The 'extend' line uses a column that does not exist in the DeviceProcessEvents schema.

The 'extend' line references a column named 'ParentProcessFileName' that does not exist in the DeviceProcessEvents schema. The actual column is 'InitiatingProcessFileName' (or 'ParentProcessName' in some schemas). Since the column doesn't exist, the 'extend' operation fails silently or produces null values, causing the subsequent 'summarize' to group by null and return no results.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The 'extend' line creates a new column that is not used in the subsequent summarize, causing the query to not group by parent process as intended.

    Why it's wrong here

    In KQL, an 'extend' operator simply appends a computed column to the row set; if that new column isn't referenced in a later 'summarize', it has no effect on grouping or aggregation. The query groups by 'InitiatingProcessFileName', which is indeed the parent process column in DeviceProcessEvents, so the grouping logic would work as intended even if the extended column existed. Thus, the claim that an unused column prevents correct grouping is false; an unused column cannot change the result of a 'summarize by' operation.

  • ✗

    The 'summarize' operator cannot be used with 'count()' in this context.

    Why it's wrong here

    `summarize count()` is a fundamental and valid aggregation in Kusto—it counts the number of rows in each group defined by the subsequent 'by' clause. For instance, `summarize count() by InitiatingProcessFileName` produces a table with the count of events per parent process. There is no contextual limitation that makes count() invalid here; count() is shorthand for count(1) and is widely used in threat hunting queries. Therefore, this cannot be the reason the query fails.

  • ✗

    The 'where' clause filters out all events because the FileName list is incorrect.

    Why it's wrong here

    The 'where' clause is used to filter events, but the file names listed are genuine process executables that exist in the DeviceProcessEvents data, such as 'powershell.exe' or 'cmd.exe'. Filtering with a valid 'in' list does not automatically suppress all rows because the table contains events referencing these executables. Additionally, if the goal is to detect suspicious activity, these are common attack tools, so the list is intentionally not empty. The query failure occurs upstream, not because the filter values are illegitimate.

  • ✓

    The 'extend' line uses a column that does not exist in the DeviceProcessEvents schema.

    Why this is correct

    According to the Microsoft 365 Defender DeviceProcessEvents schema, there is no valid column named 'InitiatingProcessParentFileName'; the correct field for the parent process executable is 'InitiatingProcessFileName'. An 'extend' expression that references a non-existent column causes a Kusto semantic error, because schema validation rejects the unrecognized identifier. As a result, the entire query fails or returns an empty result set, rather than creating a new column. This schema mismatch is the direct cause of the issue.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.