Courseiva
Perform threat hunting →mediumMultiple Choice

SC-200 Perform threat hunting Practice Question

You are a threat hunter in a Microsoft Sentinel environment that ingests both Microsoft Defender XDR and third-party network logs. You want to build a reusable hunting query that surfaces failed authentication attempts from IP addresses that have never before been associated with successful sign-ins in your tenant. Which KQL operator should you use to correlate the two datasets and return only the novel source IPs?

⚠ Common exam trap

The trap here is assuming an inner join is needed to correlate datasets, when the requirement is to exclude known-good IPs and only a leftanti join preserves unmatched left-side rows.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

leftanti join between SigninLogs and the successful sign-in set

The hunt hypothesis depends on identifying source IPs that generate failures but have no history of successful authentication. A leftanti join preserves the left-side failed sign-in rows and drops any whose IP key appears in the right-side success set, yielding the novel addresses the analyst wants to investigate further.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    union of SigninLogs and the successful sign-in set

    Why it's wrong here

    union appends rows from both tables and does not filter by matching keys. It would produce a combined stream of all sign-in events, including IPs already known to authenticate successfully, so it cannot isolate the never-before-seen source addresses.

  • ✗

    summarize count() by IPAddress on SigninLogs only

    Why it's wrong here

    Aggregating only the failed sign-in table gives counts per IP but has no knowledge of which IPs previously succeeded. Without correlating to the success dataset, addresses that routinely authenticate successfully would be incorrectly reported as novel.

  • ✓

    leftanti join between SigninLogs and the successful sign-in set

    Why this is correct

    A leftanti join returns rows from the left table that have no match in the right table. By joining failed sign-in records against the historical successful sign-in IP set, you get exactly the source IPs with failures but no prior success, which is the novel-IP condition the hunt requires.

  • ✗

    inner join between SigninLogs and the successful sign-in set

    Why it's wrong here

    An inner join keeps only rows where the IP exists in both datasets. That would return IPs that have both failed and succeeded, the opposite of the novel-IP set you want. It cannot surface IPs that appear only in the failed sign-in data.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.