SC-200 Manage a security operations environment Practice Question
Exhibit
Refer to the exhibit. ```kusto SecurityAlert | where TimeGenerated > ago(7d) | where AlertName == "Suspicious process execution" | extend Entities = parse_json(Entities) | mv-expand Entities | where Entities.Type == "account" | project AccountUpn = Entities.Upn, AlertName, TimeGenerated | summarize Count = count() by AccountUpn | where Count > 5 ```
Refer to the exhibit. You are reviewing a KQL query used in a Microsoft Sentinel scheduled analytics rule. What is the primary purpose of this query?
⚠ Common exam trap
Watch out — candidates often confuse counting process alerts (EventID 4688) with counting incidents or false positives, leading them to select options B or C without recognizing the query's focus on raw event aggregation over a specific time window.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
To detect accounts that have triggered a high number of suspicious process alerts within 7 days
The query uses `summarize` with `dcount(EventID)` to count distinct process creation events per account, then filters for accounts with a count greater than 10 using `where EventCount > 10`. The `where TimeGenerated > ago(7d)` restricts the time window to the last 7 days. This pattern is designed to detect accounts that have triggered a high number of suspicious process alerts (EventID 4688) within a week, making D correct.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
To investigate a new type of attack pattern
Why it's wrong here
The KQL query references a specific, known alert type—it filters on a fixed alert name (e.g., 'Suspicious process executed') and then aggregates counts. Investigating a new attack pattern requires exploratory searches across raw event tables with pattern detection or baseline anomaly analysis, not a rule‑bound alert aggregation. Because the query starts from a predetermined detection name, it can only shed light on variations of a known behavior, never on unreported or novel attack techniques.
- ✗
To identify which accounts are associated with the most incidents
Why it's wrong here
The query groups and counts alerts by account, not incidents; incidents are the correlated, triaged case entities that may bundle multiple alerts. To rank accounts by incident count you would need to join SecurityIncident with SecurityAlert, group by the affected account through entity mapping, and then count incident IDs. This query operates entirely on the alert table (or similar), so it can never produce an incident-centric view, nor does it include the correlation logic that distinguishes incidents from raw alerts.
- ✗
To find accounts that have generated false positive alerts
Why it's wrong here
The query does not incorporate any field that records alert classification, such as triage status, rep, or analytics rule's false-positive tuning. It merely calculates the number of suspicious process alerts per account over the last 7 days; a high count could indicate legitimate admin activity or a compromised user, indistinguishable from false positives. To find false positives you would need to inspect the actual process execution details (e.g., path, command line) and compare against customer-approved software baselines or look at the 'remediation' and 'status' columns in the incident/alert tables.
- ✓
To detect accounts that have triggered a high number of suspicious process alerts within 7 days
Why this is correct
This query correctly identifies accounts that fire a high number of 'suspicious process' alerts within a 7-day lookback. It uses a filter for that alert name, summarize by AccountName to count occurrences, and then sets a threshold of more than 5 alerts—surfacing users whose process execution behavior is repeatedly flagged as suspicious. The time window and threshold are both configurable, thereby allowing defenders to tune the query to their environment's baseline noise.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
2 more ways this is tested on SC-200
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Refer to the exhibit. You run this KQL query in Microsoft Sentinel. What is the purpose of the query?
easy- A.To list all incidents in the last 7 days
- ✓ B.To count alerts by severity over the last week
- C.To find the most recent high-severity alert
- D.To identify hunting results
Why B: The KQL query uses the `SecurityAlert` table and summarizes alerts by `AlertSeverity` using the `count()` aggregation function. The `where TimeGenerated > ago(7d)` filter restricts results to the last 7 days, and the `project` clause outputs only the severity and count columns. This directly produces a count of alerts grouped by severity over the last week, matching option B.
Variation 2. You are reviewing the KQL query shown in the exhibit. What is the purpose of this query?
medium- A.Count the number of high-severity alerts per hour
- B.Return the timestamp of each high-severity alert
- ✓ C.Identify high-severity alert names that occurred more than 10 times in the last 24 hours
- D.List all high-severity incidents in the last 24 hours
Why C: The query uses `summarize` with `count()` on `AlertName`, then filters with `where count_ > 10`. This groups high-severity alerts by name and returns only those names that appear more than 10 times in the last 24 hours. The `project` statement outputs only the `AlertName` and its count, confirming the purpose is to identify frequently occurring high-severity alert names.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.