SC-200 Manage a security operations environment Practice Question
Exhibit
Refer to the exhibit. ```kusto SecurityIncident | where TimeGenerated > ago(7d) | summarize TotalIncidents = count() by Owner | where TotalIncidents > 10 | project Owner, TotalIncidents ```
Refer to the exhibit. You run the KQL query in Microsoft Sentinel to identify analysts with high incident assignments. The query returns no results, but you know incidents exist. What is the most likely reason?
⚠ Common exam trap
Microsoft often tests the nuance that KQL aggregation operators like summarize exclude null group-by keys by default, leading candidates to overlook the data quality issue and instead blame syntax or table existence.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Incidents are not assigned to any owner, so the Owner field is null
If incidents have no assigned owner, the Owner field is null. The KQL query likely filters or groups by Owner, and null values are excluded from results by default in aggregation operations like summarize. Since incidents exist but are unassigned, the query returns no results.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The summarize operator is incorrectly used
Why it's wrong here
The summarize operator in KQL is syntactically valid and correctly groups rows by the Owner field while computing an aggregate like count(). If the operator were misused, the query would produce a semantic or syntax error and fail to execute, rather than silently returning a table with zero rows. The actual problem is downstream: the query aggregates null-owner incidents but then filters that group out using a comparison that does not match null values.
- ✗
The SecurityIncident table does not exist
Why it's wrong here
SecurityIncident is a core schema table in Microsoft Sentinel, populated by default through the Microsoft Security Incident connector and used in many built-in analytics rules. If the table were absent, the query would fail at the very first line with a clear semantic error indicating that the table or function was not found, so the query would never reach the summarize or filter stages. Since the query executes and yields results, the table definitely exists.
- ✗
The query period is too short to capture incidents
Why it's wrong here
A 7-day time filter is unlikely to be the cause because Sentinel retains incident data for a much longer period (typically at least 90 days), and the ago(7d) function excludes only older records while still capturing any incidents created within the last week. If there were any incidents during that window, they would be scanned and processed by the query; an empty result is not explained by the time range but by how null owner values are handled in the where clause.
- ✓
Incidents are not assigned to any owner, so the Owner field is null
Why this is correct
In Sentinel, the Owner field is nullable, and incidents that have not yet been assigned to an analyst or group will contain a null value rather than an empty string. When you summarize by Owner, null values are grouped into a single bucket, but KQL does not consider a null value equal to null with the equality operator (==); it requires the isnull() function to test for absence. The query likely filters with something like where Owner == null, which evaluates to false for all rows and omits the exact incidents the user intended to count, resulting in zero incidents being returned.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.