SC-200 Perform threat hunting Practice Question
During a threat hunt, a security analyst uses Microsoft Sentinel and identifies a series of failed logon attempts from a single IP address targeting multiple user accounts. The analyst wants to create a scheduled analytics rule that generates an alert when the same IP address fails to logon to more than 10 different accounts within 5 minutes. Which KQL operator should be used to count distinct accounts per IP?
⚠ Common exam trap
SC-200 often tests the difference between count() and dcount() in KQL — candidates confuse counting all rows with counting distinct values, leading to incorrect detection logic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
dcount(Account)
The dcount(Account) operator is correct because it counts the number of distinct values in the Account column, which is exactly what the analyst needs: the number of unique accounts targeted by failed logons from a single IP. The full query would use summarize dcount(Account) by IPAddress and then filter for counts greater than 10 within a 5-minute window. This directly addresses the requirement to count distinct accounts per IP.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
count()
Why it's wrong here
count() alone returns the total number of rows in the result set, ignoring which accounts or IPs they belong to, so it cannot count distinct accounts per IP. It is tempting because it is the simplest aggregation, and it would be correct when the requirement is a single total event count rather than per-IP distinct account counts.
- ✗
summarize count() by Account
Why it's wrong here
summarize count() by Account counts total failed logon events per account, not distinct accounts per IP address, so it cannot detect one IP hitting more than ten accounts. It is tempting because summarize is the right aggregation operator, and it would be correct when counting total events grouped by a single dimension such as Account.
- ✗
distinct Account
Why it's wrong here
distinct returns a de-duplicated column of Account values without grouping by IP or producing a count, so it cannot yield distinct accounts per source IP. It is tempting because it removes duplicate account names, and it would be correct when listing unique values rather than aggregating them per IP within a time window.
- ✓
dcount(Account)
Why this is correct
dcount(Account) counts distinct account values per grouping, so summarising by IP with a threshold above 10 flags the same source failing against many accounts within the five-minute window. It satisfies the distinct-account counting requirement precisely.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.