SC-200 Manage a security operations environment Practice Question
You are a security operations engineer for a company that uses Microsoft Defender XDR. You need to create a custom detection rule that alerts when a user performs more than 10 failed logon attempts within 5 minutes from different IP addresses. The rule should use the IdentityLogonEvents table. You have written the KQL query and now need to configure the rule settings in Microsoft 365 Defender. Which configuration should you use for the rule frequency and lookback period to minimize false positives while ensuring timely detection?
⚠ Common exam trap
The trap is assuming a longer lookback always improves detection, but it actually increases false positives and can duplicate alerts; candidates may pick 1-hour lookback thinking it catches more, but it violates the 5-minute condition.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Run every 5 minutes with a 5-minute lookback.
To detect more than 10 failed logons within 5 minutes, the rule should run every 5 minutes with a 5-minute lookback so it evaluates the most recent 5-minute window each time. This minimizes false positives by focusing on the exact time window and ensures timely detection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Run every 5 minutes with a 5-minute lookback.
Why this is correct
Running every 5 minutes with a 5-minute lookback is optimal because the lookback exactly matches the execution interval, ensuring each event is evaluated exactly once within its own time window. This configuration minimizes detection latency to at most five minutes while avoiding both data gaps and overlapping evaluations. It's the standard baseline for near-real-time security alerting in tools like Microsoft Sentinel.
- ✗
Run every 5 minutes with a 1-hour lookback.
Why it's wrong here
Although a 5-minute run cadence is responsive, the 1-hour lookback creates overlapping query windows in which the same event may be evaluated multiple times, producing duplicate alerts or inflated incident counts. The longer window also aggregates events across many independent sessions, which can cause unrelated activity to appear correlated and increase false positives. This wastes analyst time and degrades the precision of detection.
- ✗
Run every 1 hour with no lookback.
Why it's wrong here
Setting a 1-hour run frequency with no lookback means the query only inspects events at the exact moment of execution, completely ignoring the nearly hour of activity that occurred since the previous run. Without a lookback, there is no memory of past events, so almost all malicious activity would be missed. This configuration provides essentially no detection coverage and is worse than not running the rule at all.
- ✗
Run every 24 hours with a 24-hour lookback.
Why it's wrong here
A 24-hour run cadence with a 24-hour lookback does capture the full day's telemetry, but it delays any alert by up to 24 hours—far too slow for incident response against active threats. The coarse one-day aggregation also commingles thousands of events, making it difficult to isolate a single malicious action and often triggering a flood of alerts that overwhelm triage. This is more suited to daily compliance reporting than real-time security monitoring.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.