SC-200 Manage a security operations environment Practice Question
Exhibit
Refer to the exhibit. ```azurecli az sentinel alert-rule create \ --resource-group rg-sentinel \ --workspace-name sentinel-workspace \ --rule-name "Suspicious Sign-in" \ --rule-type Scheduled \ --query "SigninLogs | where RiskLevelDuringSignIn == 'high'" \ --display-name "Suspicious Sign-in" \ --severity High \ --enabled true ```
Refer to the exhibit. You execute the Azure CLI command to create an analytics rule in Microsoft Sentinel. The rule is created but never triggers. What is the most likely cause?
⚠ Common exam trap
A common mix-up: candidates assume a rule creation success means the query is valid, but Microsoft Sentinel does not validate column existence in KQL queries at creation time—only at execution time, leading to silent failures.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The query references a column that does not exist in SigninLogs
If the KQL query in the analytics rule references a column that does not exist in the SigninLogs table, the query will run but return zero results (or an error depending on the query structure), causing the rule to never trigger an alert. In Microsoft Sentinel, analytics rules rely on the query to produce matching results; if the column name is misspelled or absent, no events will match the rule conditions, so no incidents are generated.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The query references a column that does not exist in SigninLogs
Why this is correct
The KQL query in the rule references a column that is not present in the SigninLogs schema. The correct property is riskLevelDuringSignIn, written in camelCase, but the query uses a variant such as riskLevelDuringSignin or plain riskLevel, which Log Analytics will reject because that column does not exist. When the scheduled query runs, Kusto throws a 'column does not exist' error and returns no rows, so the rule never creates an alert.
- ✗
The --enabled parameter should be set to false
Why it's wrong here
The --enabled parameter is being handled correctly: the command sets it to true, which is required to turn the rule on. If it were set to false, the rule would be in a disabled state and would not execute at all, making it even harder to detect the real mismatch in the query column. Therefore, the enabled flag is not the cause of the rule failing to trigger.
- ✗
The severity must be set to Low for the rule to trigger
Why it's wrong here
Severity does not control whether an analytics rule fires; Low, Medium, High, and Informational are just labels assigned to incidents after a rule has already triggered. The trigger condition is determined solely by whether the KQL query returns a result, not by the incident severity value. Changing the severity to Low leaves the invalid column reference untouched, so the rule would still fail.
- ✗
The resource group name is incorrect
Why it's wrong here
The resource group name in the exhibit is correct, and even if it were wrong, the Azure CLI would immediately fail with a resource-not-found error during deployment rather than silently allow the rule to exist and simply not trigger. An incorrect resource group would prevent the rule from being created at all, but the user successfully created it, as evidenced by the issue occurring only when the rule runs. Thus, this option does not explain the absence of alerts.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.