Courseiva

SC-200 Manage a security operations environment Practice Question

You are a security operations analyst for a company that uses Microsoft Sentinel. You need to create a workbook that displays the top 10 most common alert types over the last 7 days. The workbook will be used by the SOC manager to identify trends. You have already created a new workbook and added a query step. Which KQL query should you use in the query step?

⚠ Common exam trap

Watch out — candidates often confuse the `project` operator with `summarize`, mistakenly thinking they can use `count()` in a `project` clause, or they choose a query that shows alert volume over time instead of the top alert types by name.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AlertInfo | where TimeGenerated > ago(7d) | summarize Count = count() by AlertName | top 10 by Count desc | render barchart

It uses the `summarize` operator to count alerts by `AlertName`, then `top 10 by Count desc` to return the ten most frequent alert types, and `render barchart` to visualize the data in the workbook. This directly meets the requirement to display the top 10 most common alert types over the last 7 days.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AlertInfo | where TimeGenerated > ago(7d) | project AlertName

    Why it's wrong here

    This query filters alerts from the last 7 days and then projects only the AlertName column, yielding one row per alert without any counting or grouping. As a result, it produces a raw list of alert names, not a summarized frequency distribution, so it cannot reveal the top 10 most frequent alert types. To answer the question, the query must aggregate counts per AlertName and then select the largest counts.

  • ✗

    AlertInfo | where TimeGenerated > ago(7d) | project AlertName, count()

    Why it's wrong here

    The project operator is used to select columns, but count() is an aggregation function that must be used within the summarize operator; outside of summarize, count() has no meaning and will generate a syntax error. The query also fails to group by AlertName, so it cannot compute per-alert frequencies. A correct approach would use summarize Count = count() by AlertName, then apply top 10 and render a bar chart.

  • ✓

    AlertInfo | where TimeGenerated > ago(7d) | summarize Count = count() by AlertName | top 10 by Count desc | render barchart

    Why this is correct

    This query filters alerts from the last 7 days, then groups them by AlertName using summarize to count occurrences per alert type. The top 10 operator sorts the aggregated counts in descending order and returns the ten alert names with the highest frequencies, and render barchart visualizes the result as a bar chart. This satisfies the requirement to display the top 10 alert names by count.

  • ✗

    AlertInfo | where TimeGenerated > ago(7d) | summarize count() by bin(TimeGenerated, 1d) | render timechart

    Why it's wrong here

    This query groups alerts by daily time bins using bin(TimeGenerated, 1d) and counts alerts per day, then renders a timechart showing alert volume over time. While it uses aggregation correctly, it does not group by AlertName or sort by count, so it cannot identify the top 10 alert names. The chart answers a different question: 'How many alerts occurred each day?' rather than 'Which alert types are most frequent?'

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.