Courseiva

SC-200 Manage a security operations environment Practice Question

Exhibit

Refer to the exhibit.

```kusto
SecurityIncident
| where TimeGenerated > ago(7d)
| summarize TotalIncidents = count() by Owner
| where TotalIncidents > 10
| project Owner, TotalIncidents
```

Refer to the exhibit. You run the KQL query in Microsoft Sentinel to identify analysts with high incident assignments. The query returns no results, but you know incidents exist. What is the most likely reason?

⚠ Common exam trap

Microsoft often tests the nuance that KQL aggregation operators like summarize exclude null group-by keys by default, leading candidates to overlook the data quality issue and instead blame syntax or table existence.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Incidents are not assigned to any owner, so the Owner field is null

If incidents have no assigned owner, the Owner field is null. The KQL query likely filters or groups by Owner, and null values are excluded from results by default in aggregation operations like summarize. Since incidents exist but are unassigned, the query returns no results.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The summarize operator is incorrectly used

    Why it's wrong here

    The summarize operator in KQL is syntactically valid and correctly groups rows by the Owner field while computing an aggregate like count(). If the operator were misused, the query would produce a semantic or syntax error and fail to execute, rather than silently returning a table with zero rows. The actual problem is downstream: the query aggregates null-owner incidents but then filters that group out using a comparison that does not match null values.

  • ✗

    The SecurityIncident table does not exist

    Why it's wrong here

    SecurityIncident is a core schema table in Microsoft Sentinel, populated by default through the Microsoft Security Incident connector and used in many built-in analytics rules. If the table were absent, the query would fail at the very first line with a clear semantic error indicating that the table or function was not found, so the query would never reach the summarize or filter stages. Since the query executes and yields results, the table definitely exists.

  • ✗

    The query period is too short to capture incidents

    Why it's wrong here

    A 7-day time filter is unlikely to be the cause because Sentinel retains incident data for a much longer period (typically at least 90 days), and the ago(7d) function excludes only older records while still capturing any incidents created within the last week. If there were any incidents during that window, they would be scanned and processed by the query; an empty result is not explained by the time range but by how null owner values are handled in the where clause.

  • ✓

    Incidents are not assigned to any owner, so the Owner field is null

    Why this is correct

    In Sentinel, the Owner field is nullable, and incidents that have not yet been assigned to an analyst or group will contain a null value rather than an empty string. When you summarize by Owner, null values are grouped into a single bucket, but KQL does not consider a null value equal to null with the equality operator (==); it requires the isnull() function to test for absence. The query likely filters with something like where Owner == null, which evaluates to false for all rows and omits the exact incidents the user intended to count, resulting in zero incidents being returned.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.