SC-200 Manage a security operations environment Practice Question
Exhibit
Refer to the exhibit.
```json
{
"properties": {
"ruleId": "6b1c0a1e-0e1f-4b1a-8e1f-1a2b3c4d5e6f",
"displayName": "Suspicious Sign-in from Anonymous IP",
"enabled": true,
"query": "SigninLogs
| where Location == 'Unknown'
| where TimeGenerated > ago(7d)
| summarize count() by UserPrincipalName
| where count_ > 3",
"queryFrequency": "PT1H",
"queryPeriod": "PT7D",
"triggerOperator": "GreaterThan",
"triggerThreshold": 0,
"severity": "Medium",
"suppressionDuration": "PT6H",
"suppressionEnabled": true
}
}
```Refer to the exhibit. You are reviewing an analytics rule in Microsoft Sentinel. The rule is enabled but has not generated any alerts in the past 24 hours. What is the most likely cause?
⚠ Common exam trap
Be careful: suppression does not stop the first alert from being generated; it only suppresses subsequent matching results for the configured duration. A rule with no alerts in the past 24 hours means the query likely returned no results or the rule isn't running, not that suppression is suppressing everything.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The query uses 'Location == Unknown' but the actual sign-in location is not 'Unknown'
The rule has generated no alerts because the query condition 'Location == Unknown' does not match any actual sign-in locations. Suppression only suppresses alerts after an initial alert has been generated; it does not prevent the first alert. With zero alerts, the most likely cause is that the query returns no results, not suppression.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The triggerThreshold is set to 0, which means no alerts will be generated
Why it's wrong here
In Microsoft Sentinel, a scheduled rule's triggerThreshold defines the number of query results required to generate an alert, not a count of alerts to suppress. Setting triggerThreshold to 0 makes the rule fire whenever the query returns at least one row, so it actually maximizes alert generation rather than preventing it. This option is incorrect because a zero threshold means 'match on any result,' not 'never trigger.'
- ✗
Suppression is enabled with a duration of 6 hours, which may be suppressing new alerts after the first one
Why it's wrong here
When the rule is configured with Alert Suppression enabled for 6 hours, the first time the query produces a result and creates an alert, the rule's subsequent scheduled executions will be stopped or suppressed for the entire 6-hour window. During that window, even if new sign-in events with 'Unknown' location occur, the rule will not generate additional alerts, so you only see the initial alert. This perfectly explains the apparent shortage of alerts, as one alert every 6 hours may be all that is produced even with continuous matches.
- ✗
The queryFrequency is 1 hour and the queryPeriod is 7 days, which is a mismatch
Why it's wrong here
A queryFrequency of 1 hour with a queryPeriod of 7 days is a supported and intentional pattern in Microsoft Sentinel. The rule runs every hour but evaluates the 7-day dataset at each run, allowing the detection logic to consider long-term context; this lookback is useful for time-series or anomaly patterns. This is not a configuration mismatch, so it cannot be the reason alerts appear to be missing.
- ✓
The query uses 'Location == Unknown' but the actual sign-in location is not 'Unknown'
Why this is correct
The filter 'Location == Unknown' makes the rule alert only when the sign-in location is reported as Unknown, which is a data-quality attribute. If the actual sign-in location is, say, 'United States,' the query simply returns no records and the rule remains silent—this is the rule working as designed, not a misconfiguration. If you are expecting an alert for a known-location sign-in, this rule was never meant to cover it; and if unknown-location sign-ins did occur, suppression, not the location filter, would prevent duplicates.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.