Courseiva

SC-200 Manage a security operations environment Practice Question

You are a security analyst at a company that uses Microsoft Sentinel. You need to create a custom analytics rule that detects failed logon attempts from multiple IP addresses within 5 minutes. Which two KQL operators should you use?

⚠ Common exam trap

It's easy for candidates to confuse `where` or `project` as sufficient for time-window analysis, failing to recognize that only `bin` with `summarize` can group events into fixed intervals and aggregate distinct IPs per interval.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

bin

The `bin` operator is correct because it groups timestamps into fixed-size time buckets (e.g., 5-minute intervals), which is essential for detecting patterns like failed logon attempts from multiple IPs within a specific time window. The `summarize` operator is correct because it aggregates data (e.g., counting distinct IP addresses) per each time bucket, enabling the rule to identify when the count exceeds a threshold.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    where

    Why it's wrong here

    where filters rows based on condition expressions but does not perform aggregation or time-window grouping. It can narrow the dataset before aggregation, yet by itself it cannot consolidate multiple events into a single aggregate output like a count per hour. The row count and granularity remain unchanged after a where operation. In KQL, where is strictly a row-level filter, not an aggregation operator.

  • ✗

    project

    Why it's wrong here

    project selects and renames columns to shape the output schema, but it operates row-by-row and never reduces the number of rows. It cannot group events into time windows or compute sums or counts because it only modifies the column list. Project leaves every input row intact, just with a different set of columns. In KQL, project is a tabular shaping operator, not an aggregation operator.

  • ✓

    bin

    Why this is correct

    bin (sometimes called floor) rounds numeric values down to the nearest multiple of a specified bin size, creating discrete time buckets such as bin(timestamp, 1h). This function is essential for time-window grouping because it assigns each event to a specific bucket, which can then be used as a grouping key in summarize. By itself, bin does not aggregate; it only produces a grouping value. When combined with summarize, it enables time-series aggregations like count per hour, making it the correct choice for creating time windows.

  • ✗

    join

    Why it's wrong here

    join merges rows from two tables based on matching keys, similar to SQL joins, and typically increases or horizontally combines columns and rows. It does not perform any aggregation or create time-window groups; it is a relational operator used to correlate data sets. Join leaves the granularity of the input tables largely unchanged, though duplicate matches can multiply rows. While join can be used in queries that also aggregate, it is not the operator responsible for grouping or computing aggregates.

  • ✓

    summarize

    Why this is correct

    summarize aggregates rows by grouping on one or more keys and computing measures such as count(), sum(), avg(), or dcount(). In KQL, summarize is the primary aggregation operator and works hand-in-hand with bin when you need time-window groups, as in summarize count() by bin(timestamp, 1h). It reduces the row count to one row per distinct combination of grouping expressions. Without summarize, no aggregation occurs, so it is one of the two correct answers when the goal is to group data into time windows.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.