Courseiva

SC-200 Manage a security operations environment Practice Question

You are a security operations analyst using Microsoft Sentinel. You need to configure a workbook that displays a map of failed sign-in attempts by location over the last 24 hours. The data is stored in the SigninLogs table. Which two elements must you include in the workbook to achieve this?

⚠ Common exam trap

The trap here is assuming that any visualization can display location data, when only specific map visualizations can plot geographic coordinates.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A query that summarizes failed sign-ins by location and a map visualization.

To create a map in a Microsoft Sentinel workbook, you need a query that returns location data (such as latitude and longitude or country) and a map visualization that interprets that data. The query should filter for failed sign-ins in the last 24 hours and summarize by location. Other visualizations like pie charts or time charts do not display geographic information effectively.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A query that counts failed sign-ins by user and a time chart visualization.

    Why it's wrong here

    Counting by user would not provide geographic distribution, and a time chart shows trends over time, not locations. The requirement is to display a map by location, so aggregating by user and using a time chart is incorrect. The query should group by location, and the visualization should be a map.

  • ✗

    A query that joins SigninLogs with Heartbeat and a grid visualization.

    Why it's wrong here

    Joining with Heartbeat is unnecessary and irrelevant for sign-in location data. A grid visualization would show tabular data, not a map. The requirement is to visualize on a map, so a map visualization is needed. The query should focus on SigninLogs and aggregate by location.

  • ✓

    A query that summarizes failed sign-ins by location and a map visualization.

    Why this is correct

    This is correct because to display a map, you need a query that aggregates data by location (e.g., using the location field) and a map visualization that plots those locations. The query should filter for failed sign-ins in the last 24 hours and group by location to provide the necessary data points.

  • ✗

    A query that lists all sign-in events and a pie chart visualization.

    Why it's wrong here

    Listing all sign-in events would not provide a summary by location, and a pie chart is not suitable for geographic data. A map visualization is specifically designed to display location-based data. The requirement is to show failed sign-ins by location on a map, so this approach does not meet the need.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.