SC-200 Perform threat hunting Practice Question
You are a threat hunter in a Microsoft Sentinel environment that ingests both Microsoft Defender XDR and third-party network logs. You want to build a reusable hunting query that surfaces failed authentication attempts from IP addresses that have never before been associated with successful sign-ins in your tenant. Which KQL operator should you use to correlate the two datasets and return only the novel source IPs?
⚠ Common exam trap
The trap here is assuming an inner join is needed to correlate datasets, when the requirement is to exclude known-good IPs and only a leftanti join preserves unmatched left-side rows.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
leftanti join between SigninLogs and the successful sign-in set
The hunt hypothesis depends on identifying source IPs that generate failures but have no history of successful authentication. A leftanti join preserves the left-side failed sign-in rows and drops any whose IP key appears in the right-side success set, yielding the novel addresses the analyst wants to investigate further.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
union of SigninLogs and the successful sign-in set
Why it's wrong here
union appends rows from both tables and does not filter by matching keys. It would produce a combined stream of all sign-in events, including IPs already known to authenticate successfully, so it cannot isolate the never-before-seen source addresses.
- ✗
summarize count() by IPAddress on SigninLogs only
Why it's wrong here
Aggregating only the failed sign-in table gives counts per IP but has no knowledge of which IPs previously succeeded. Without correlating to the success dataset, addresses that routinely authenticate successfully would be incorrectly reported as novel.
- ✓
leftanti join between SigninLogs and the successful sign-in set
Why this is correct
A leftanti join returns rows from the left table that have no match in the right table. By joining failed sign-in records against the historical successful sign-in IP set, you get exactly the source IPs with failures but no prior success, which is the novel-IP condition the hunt requires.
- ✗
inner join between SigninLogs and the successful sign-in set
Why it's wrong here
An inner join keeps only rows where the IP exists in both datasets. That would return IPs that have both failed and succeeded, the opposite of the novel-IP set you want. It cannot surface IPs that appear only in the failed sign-in data.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.