Courseiva

SC-200 Manage a security operations environment Practice Question

Exhibit

Refer to the exhibit.

```kusto
SecurityAlert
| where TimeGenerated > ago(7d)
| where AlertSeverity == "High"
| where ProviderName == "Microsoft Defender for Endpoint"
| summarize AlertCount = count() by AlertName, bin(TimeGenerated, 1d)
| sort by AlertCount desc
```

Refer to the exhibit. You are analyzing high severity alerts from Microsoft Defender for Endpoint in Microsoft Sentinel. What does this KQL query do?

⚠ Common exam trap

Microsoft often tests the distinction between summarizing aggregated data (counts) versus displaying raw event details, so candidates mistakenly choose 'displays detailed properties' when the query uses `summarize` and `count()`.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

It lists high severity Defender for Endpoint alerts, grouped by name and day, ordered by frequency

The KQL query uses `summarize` with `count()` to group alerts by `AlertName` and `startofday(TimeGenerated)`, then sorts by `count_` descending. This directly produces a list of high severity Defender for Endpoint alerts grouped by name and day, ordered by frequency, matching option C.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    It counts alerts for a specific alert name

    Why it's wrong here

    The query does not filter for a single alert name; it aggregates across every distinct alert name in the SecurityAlert table. The `summarize count() by AlertName` clause groups all alert names that match the high-severity Defender for Endpoint filter, producing a separate count for each. Without a `where AlertName == "..."` condition, the query's scope is the entire set of matching alerts, not one specific name.

  • ✗

    It displays detailed properties of each alert

    Why it's wrong here

    The query aggregates data using `summarize` rather than returning raw alert records. Aggregated output contains only the grouping columns (AlertName, TimeGenerated bucket) and a `count_` column, not individual alert properties such as AlertType, Tactics, or Entities. A query that displays detailed properties would use `project`, `extend`, or simply `SecurityAlert | where ...` without a summarize, so this option mischaracterizes the query's output shape.

  • ✓

    It lists high severity Defender for Endpoint alerts, grouped by name and day, ordered by frequency

    Why this is correct

    This option correctly describes the query: it filters SecurityAlert for ProviderName == "Microsoft Defender for Endpoint" and Severity == "High", then performs `summarize Count = count() by AlertName, bin(TimeGenerated, 1d)` to group alerts by name and day. Finally, it orders the results by Count descending, which ranks the alert names by frequency. The output is a summary list, not individual alerts, matching the exact behavior of a KQL aggregation query.

  • ✗

    It shows all alerts from Defender for Endpoint in the last week

    Why it's wrong here

    The query explicitly filters for high severity alerts and restricts the provider to Microsoft Defender for Endpoint. It does not return all Defender for Endpoint alerts; it excludes medium, low, and informational alerts. Additionally, the time filter (for example, `TimeGenerated > ago(7d)`) limits the window, but the severity and provider filters make the result set a narrow subset rather than 'all alerts'.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.