Courseiva

SC-200 Respond to security incidents Practice Question

Exhibit

Refer to the exhibit. The following KQL query is used in a Microsoft Sentinel analytics rule to detect anomalous Microsoft Entra ID sign-ins:

```kql
let threshold = 10;
SigninLogs
| where TimeGenerated > ago(1h)
| summarize count() by UserPrincipalName, IPAddress
| where count_ > threshold
| join kind=inner (SigninLogs
| where TimeGenerated > ago(1h)
| where RiskLevelDuringSignIn == "high")
on UserPrincipalName, IPAddress
```

The analyst notices that the rule does not fire for a user who has 12 sign-ins from the same IP address, but all are low risk. The expected behavior is to alert when a single user has more than 10 sign-ins from the same IP with at least one high-risk sign-in. What is the issue?

⚠ Common exam trap

The trap here is that candidates focus on the numeric threshold (10 vs. 12) and overlook the join logic, assuming the rule should fire because the count exceeds the threshold, when in fact the join condition is the root cause of the failure.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The query requires a high-risk sign-in from the same IP, but none exist, so no match.

The KQL query uses an inner join on UserPrincipalName and IPAddress, which only returns rows where a high-risk sign-in exists from the same IP. Since all 12 sign-ins from that IP are low risk, the join produces no matching rows, and the rule does not fire. The threshold of 10 is irrelevant when the join condition fails to produce any results.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The join should be on UserPrincipalName only, not IPAddress.

    Why it's wrong here

    Changing the join to UserPrincipalName only would match any high-risk sign-in by the user regardless of source IP. The rule's intent is to require a high-risk sign-in from the exact same IP address as the other sign-ins. Removing IPAddress from the join key broadens the match and could cause the rule to fire for users whose high-risk activity came from a different IP, so the original join is correct.

  • ✗

    The join should be leftouter to include sign-ins without high risk.

    Why it's wrong here

    A leftouter join would keep every sign-in row even when no high-risk sign-in exists for that user and IP. The rule explicitly requires at least one high-risk sign-in; including non-matching rows would let users with zero high-risk events accumulate enough sign-ins to pass the threshold. The inner join is necessary to enforce the high-risk prerequisite before count evaluation.

  • ✗

    The threshold is set to 10, but the user has 12 sign-ins, so it should fire.

    Why it's wrong here

    The threshold is applied in the summarize step after the join has already filtered rows. Because this user has no high-risk sign-in from the same IP, the inner join produces zero rows for them, so the later count never sees the 12 sign-ins. The threshold being set to 10 is irrelevant if the join condition eliminates all rows; the rule fires only when high-risk rows survive the join.

  • ✓

    The query requires a high-risk sign-in from the same IP, but none exist, so no match.

    Why this is correct

    The default inner join in KQL returns only rows where both UserPrincipalName and IPAddress match between the sign-in dataset and the high-risk dataset. If this user has no high-risk sign-in that originated from the same IP, the join output is empty and the subsequent aggregation returns no result. Therefore the rule correctly does not fire, because the core condition—a high-risk event at the same source IP—is not satisfied.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.