Courseiva

SC-200 Respond to security incidents Practice Question

Exhibit

Refer to the exhibit.
```kusto
SecurityAlert
| where TimeGenerated > ago(1d)
| where AlertName contains "malware"
| extend parsed = parse_json(ExtendedProperties)
| where parsed.IPAddress == "10.0.0.5"
| project AlertName, TimeGenerated, IPAddress = parsed.IPAddress, AccountUpn = parsed.AccountUpn
```

Refer to the exhibit. A security analyst runs this KQL query in Microsoft Sentinel during an investigation. The analyst expects to see alerts related to malware from IP 10.0.0.5 but receives no results. The SecurityAlert table contains data from the last 24 hours. What is the most likely reason for no results?

⚠ Common exam trap

SC-200 often tests the assumption that column names and JSON keys are consistent across all alert providers — candidates assume 'IPAddress' is a standard key in ExtendedProperties, when in reality the schema is provider-dependent and must be verified.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The ExtendedProperties column does not contain a key named 'IPAddress' for these alerts.

The most likely reason for no results is that the ExtendedProperties column does not contain a key named 'IPAddress' for these alerts. In Microsoft Sentinel, the SecurityAlert table stores additional alert details in the ExtendedProperties column as a dynamic (JSON) field, and the specific key name varies by alert provider — if the key is not 'IPAddress', the query filter returns nothing.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The ExtendedProperties column does not contain a key named 'IPAddress' for these alerts.

    Why this is correct

    The query filters on ExtendedProperties parsing a key named IPAddress. If the alerts store the address under a different key or format, the dynamic field access returns null and every row is filtered out, so no results appear despite matching data existing in the table.

  • ✗

    The 'contains' operator is case-sensitive.

    Why it's wrong here

    KQL's contains operator is case-insensitive by default, so casing cannot suppress matches. It is tempting because case sensitivity genuinely breaks queries in other languages and in has_cs variants, but the actual failure here is the field being filtered, not the operator's casing behaviour.

  • ✗

    The time filter 'ago(1d)' is too restrictive; should use 'ago(7d)'.

    Why it's wrong here

    The stem states SecurityAlert already holds data from the last 24 hours, so ago(1d) covers the full retention window; widening to ago(7d) returns nothing extra. It is tempting because time filters commonly cause empty results, but here the filter matches the available data, so the fault lies elsewhere in the query.

  • ✗

    The 'project' statement drops the necessary columns.

    Why it's wrong here

    project selects and renames columns in the output; it does not remove rows, so it cannot cause an empty result set. It is tempting because dropping a filtered column would break later references, but the query returns no rows at all, meaning the filter itself, not the projection, is at fault.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.