Courseiva
mediumMatching

SC-200 Practice Question: Match each Kusto Query Language (KQL) operator to…

Match each Kusto Query Language (KQL) operator to its function.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Filters rows based on a condition

Groups rows and calculates aggregates

Selects specific columns

Creates computed columns

Combines rows from two tables

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

where: Filters rows based on a condition

These are fundamental KQL operators used in Microsoft Sentinel and Defender queries.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    where: Filters rows based on a condition

    Why this is correct

    The where operator evaluates a Boolean predicate against each row of the input table and returns only the rows for which the predicate evaluates to true. It is equivalent to the WHERE clause in SQL and is typically used early in a query to reduce the dataset before further processing. Because it filters at the row level, it never changes the schema or the number of columns.

  • ✓

    summarize: Aggregates rows into groups

    Why this is correct

    The summarize operator groups rows by one or more key columns (or by the entire table if no grouping keys are given) and applies one or more aggregation functions such as count(), sum(), avg(), min(), max(), or dcount(). It returns a new table with one row per distinct group, effectively reducing the row count while reshaping the data to produce summary statistics. Unlike where, it does not filter individual rows; it aggregates them.

  • ✓

    project: Selects specific columns

    Why this is correct

    The project operator selects a specified subset of columns from the input table and returns only those columns, optionally renaming them or reordering them in the output. It reduces the width of the table by dropping unselected columns, which can improve performance when working with wide tables. Project can also compute new columns, but its primary purpose is column selection and schema shaping rather than adding columns while preserving all existing ones.

  • ✓

    extend: Creates computed columns

    Why this is correct

    The extend operator adds one or more new computed columns to the input table while preserving all existing rows and columns. Each new column is defined by an expression that references existing columns (e.g., extend TotalCost = Price * Quantity), and the row count remains unchanged. This is distinct from project, which selects a subset of columns, and from summarize, which reduces rows and applies aggregations.

  • ✗

    where: Aggregates rows into groups

    Why it's wrong here

    This statement incorrectly attributes aggregation behavior to the where operator. The where operator is strictly a row filter: it evaluates a condition for each row and keeps only those rows that satisfy the condition. It does not group rows, and it cannot apply aggregation functions like count() or sum(). Row aggregation and grouping are exclusively performed by the summarize operator.

  • ✗

    summarize: Filters rows based on a condition

    Why it's wrong here

    This statement incorrectly attributes filtering behavior to the summarize operator. The summarize operator does not evaluate per-row predicates or exclude individual rows; instead, it groups rows by key values and applies aggregation functions to produce a summarized output. Row-level filtering based on conditions is the exclusive role of the where operator. Thus, this option confuses a row-filtering operation with a row-grouping/aggregating operation.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.