SC-200 Manage a security operations environment Practice Question
You are a security analyst at a company that uses Microsoft Sentinel. You need to create a custom analytics rule that detects failed logon attempts from multiple IP addresses within 5 minutes. Which two KQL operators should you use?
⚠ Common exam trap
It's easy for candidates to confuse `where` or `project` as sufficient for time-window analysis, failing to recognize that only `bin` with `summarize` can group events into fixed intervals and aggregate distinct IPs per interval.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
bin
The `bin` operator is correct because it groups timestamps into fixed-size time buckets (e.g., 5-minute intervals), which is essential for detecting patterns like failed logon attempts from multiple IPs within a specific time window. The `summarize` operator is correct because it aggregates data (e.g., counting distinct IP addresses) per each time bucket, enabling the rule to identify when the count exceeds a threshold.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
where
Why it's wrong here
where filters rows based on condition expressions but does not perform aggregation or time-window grouping. It can narrow the dataset before aggregation, yet by itself it cannot consolidate multiple events into a single aggregate output like a count per hour. The row count and granularity remain unchanged after a where operation. In KQL, where is strictly a row-level filter, not an aggregation operator.
- ✗
project
Why it's wrong here
project selects and renames columns to shape the output schema, but it operates row-by-row and never reduces the number of rows. It cannot group events into time windows or compute sums or counts because it only modifies the column list. Project leaves every input row intact, just with a different set of columns. In KQL, project is a tabular shaping operator, not an aggregation operator.
- ✓
bin
Why this is correct
bin (sometimes called floor) rounds numeric values down to the nearest multiple of a specified bin size, creating discrete time buckets such as bin(timestamp, 1h). This function is essential for time-window grouping because it assigns each event to a specific bucket, which can then be used as a grouping key in summarize. By itself, bin does not aggregate; it only produces a grouping value. When combined with summarize, it enables time-series aggregations like count per hour, making it the correct choice for creating time windows.
- ✗
join
Why it's wrong here
join merges rows from two tables based on matching keys, similar to SQL joins, and typically increases or horizontally combines columns and rows. It does not perform any aggregation or create time-window groups; it is a relational operator used to correlate data sets. Join leaves the granularity of the input tables largely unchanged, though duplicate matches can multiply rows. While join can be used in queries that also aggregate, it is not the operator responsible for grouping or computing aggregates.
- ✓
summarize
Why this is correct
summarize aggregates rows by grouping on one or more keys and computing measures such as count(), sum(), avg(), or dcount(). In KQL, summarize is the primary aggregation operator and works hand-in-hand with bin when you need time-window groups, as in summarize count() by bin(timestamp, 1h). It reduces the row count to one row per distinct combination of grouping expressions. Without summarize, no aggregation occurs, so it is one of the two correct answers when the goal is to group data into time windows.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.