SC-200 Manage a security operations environment Practice Question
Exhibit
Refer to the exhibit. ```kusto SecurityAlert | where TimeGenerated > ago(7d) | where AlertSeverity == "High" | where ProviderName == "Microsoft Defender for Endpoint" | summarize AlertCount = count() by AlertName, bin(TimeGenerated, 1d) | sort by AlertCount desc ```
Refer to the exhibit. You are analyzing high severity alerts from Microsoft Defender for Endpoint in Microsoft Sentinel. What does this KQL query do?
⚠ Common exam trap
Microsoft often tests the distinction between summarizing aggregated data (counts) versus displaying raw event details, so candidates mistakenly choose 'displays detailed properties' when the query uses `summarize` and `count()`.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It lists high severity Defender for Endpoint alerts, grouped by name and day, ordered by frequency
The KQL query uses `summarize` with `count()` to group alerts by `AlertName` and `startofday(TimeGenerated)`, then sorts by `count_` descending. This directly produces a list of high severity Defender for Endpoint alerts grouped by name and day, ordered by frequency, matching option C.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
It counts alerts for a specific alert name
Why it's wrong here
The query does not filter for a single alert name; it aggregates across every distinct alert name in the SecurityAlert table. The `summarize count() by AlertName` clause groups all alert names that match the high-severity Defender for Endpoint filter, producing a separate count for each. Without a `where AlertName == "..."` condition, the query's scope is the entire set of matching alerts, not one specific name.
- ✗
It displays detailed properties of each alert
Why it's wrong here
The query aggregates data using `summarize` rather than returning raw alert records. Aggregated output contains only the grouping columns (AlertName, TimeGenerated bucket) and a `count_` column, not individual alert properties such as AlertType, Tactics, or Entities. A query that displays detailed properties would use `project`, `extend`, or simply `SecurityAlert | where ...` without a summarize, so this option mischaracterizes the query's output shape.
- ✓
It lists high severity Defender for Endpoint alerts, grouped by name and day, ordered by frequency
Why this is correct
This option correctly describes the query: it filters SecurityAlert for ProviderName == "Microsoft Defender for Endpoint" and Severity == "High", then performs `summarize Count = count() by AlertName, bin(TimeGenerated, 1d)` to group alerts by name and day. Finally, it orders the results by Count descending, which ranks the alert names by frequency. The output is a summary list, not individual alerts, matching the exact behavior of a KQL aggregation query.
- ✗
It shows all alerts from Defender for Endpoint in the last week
Why it's wrong here
The query explicitly filters for high severity alerts and restricts the provider to Microsoft Defender for Endpoint. It does not return all Defender for Endpoint alerts; it excludes medium, low, and informational alerts. Additionally, the time filter (for example, `TimeGenerated > ago(7d)`) limits the window, but the severity and provider filters make the result set a narrow subset rather than 'all alerts'.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.