SC-200 Manage a security operations environment Practice Question
Exhibit
{"query": "SecurityAlert | where TimeGenerated > ago(7d) | summarize AlertCount = count() by AlertName, Severity | order by AlertCount desc | take 10"}Refer to the exhibit. A SOC analyst runs the KQL query in Microsoft Sentinel to identify the top 10 alert names by count. They notice the results include alerts with low severity that are not relevant. What should they add to the query to focus on high-severity alerts only?
⚠ Common exam trap
The trap here is that candidates mistakenly think a `where` clause can be placed after `summarize` to filter aggregated results, but KQL requires filtering on raw columns before aggregation, and the `where` clause after `summarize` only works on aggregated columns (e.g., `count_`) unless the original column is explicitly included in the `summarize` output.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add 'where Severity == "High"' before the summarize clause.
In KQL, the `where` clause must be placed before the `summarize` clause to filter raw events before aggregation. Placing `where Severity == "High"` before `summarize` ensures that only high-severity alerts are counted, preventing low-severity alerts from appearing in the top 10 results. This is a fundamental KQL query execution order: filtering first reduces the dataset for aggregation, improving both accuracy and performance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Add 'order by Severity' to the query.
Why it's wrong here
Adding `order by Severity` only sorts the final result set, it does not remove any rows. The summarize operator has already processed every alert regardless of severity, so all non-High rows remain in the output and the compute cost is unchanged. Sorting also forces an extra full sort operation over the aggregated results, which can be expensive if the result set is large, and it does nothing to satisfy a requirement to return only High-severity alerts.
- ✗
Add 'where Severity == "High"' after the summarize clause.
Why it's wrong here
Placing `where Severity == "High"` after the summarize clause filters the aggregated output rather than the source alerts. If the query groups by Severity, this means KQL still reads and aggregates every alert in the time range, including Low and Medium, and only after aggregation discards the non-High groups. This produces the same final rows but wastes compute and can be significantly slower in a high-volume Sentinel workspace; the filter should be applied to the raw alert stream before any aggregation is performed.
- ✗
Change the time range to last 24 hours.
Why it's wrong here
Changing the time range to 'last 24 hours' narrows the dataset by time, but it does not filter by Severity at all. All alert severities (Informational, Low, Medium, High) within that window remain in the summarization pipeline, so the query would still produce the same severity distribution unless the time window itself is the actual problem. This option might complement a severity filter, but by itself it fails the requirement to return only High-severity alerts.
- ✓
Add 'where Severity == "High"' before the summarize clause.
Why this is correct
Adding `where Severity == "High"` before the summarize clause is the correct approach because it pushes the predicate as far upstream as possible in the query pipeline. KQL first restricts the alert stream to only High-severity rows, and then the summarize operator only sees and aggregates those filtered rows, reducing both I/O and aggregation cost. This aligns with Kusto best practice to filter early, and it is particularly important in Microsoft Sentinel where alert tables can contain millions of rows.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.