SC-200 Respond to security incidents Practice Question
Exhibit
Refer to the exhibit. ```KQL SecurityAlert | where TimeGenerated > ago(7d) | where AlertName == "Suspicious process injection" | summarize count() by CompromisedEntity, AlertSeverity | order by count_ desc ```
Refer to the exhibit. You are investigating incidents related to suspicious process injection. The KQL query above is run in Microsoft Sentinel. What is the purpose of this query?
⚠ Common exam trap
Test-takers frequently confuse 'listing alerts' (Option B) with 'aggregating and counting alerts' (Option C), overlooking the `summarize` and `count()` operators that transform the output from individual records to grouped counts.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
To get a count of 'Suspicious process injection' alerts grouped by compromised entity and severity, sorted by count
The query uses `summarize` with `count()` to aggregate alerts by `CompromisedEntity` and `Severity`, then sorts by the count in descending order. This directly produces a count of 'Suspicious process injection' alerts grouped by compromised entity and severity, sorted by count. The `where` clause filters for the specific alert name, and the time range is implicitly the last 7 days (as shown in the exhibit's query editor).
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
To find alerts that occurred within a specific time range
Why it's wrong here
The query relies on a relative time filter such as `where Timestamp > ago(7d)`, which is anchored to the moment the query runs rather than a fixed start and end boundary. This means you cannot target an arbitrary historical window, only a rolling window relative to the current time. Therefore, it is unsuitable for finding alerts within a specifically requested time range.
- ✗
To list all alerts of type 'Suspicious process injection' in the last 7 days
Why it's wrong here
The query uses `summarize` to roll up alerts into per-group counts, collapsing all individual alert records into aggregated rows. As a result, the output contains only the combination of `CompromisedEntity` and `Severity` with a `count_` column, not the underlying alert events themselves. You cannot retrieve the full list of alerts because the individual records are not projected or returned.
- ✓
To get a count of 'Suspicious process injection' alerts grouped by compromised entity and severity, sorted by count
Why this is correct
The query first filters to only alerts where the title equals 'Suspicious process injection', then uses `summarize count() by CompromisedEntity, Severity` to compute how many alerts fall into each entity/severity bucket. Finally, it orders the aggregated results by the count in descending order, so the highest-frequency entity/severity combinations appear first. This exactly matches the stated purpose.
- ✗
To identify the compromised entities with the highest severity alerts
Why it's wrong here
While the query does include `Severity` as a grouping dimension, it does not apply any predicate to isolate only the most severe alerts, such as `where Severity == 'High'` or `'Critical'`. It simply aggregates across all severity levels and then sorts by alert count, not by severity value. Therefore, it identifies which entity/severity pairs have the most alerts, not which compromised entities have the highest severity alerts.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.