SC-200 summarize Practice Question
You are a threat hunter using Microsoft Sentinel. You have ingested syslog data from a Palo Alto firewall. You want to create a scheduled query rule that alerts when more than 10 outbound connections to a known bad IP address occur within 5 minutes. Which KQL function should you use to summarize the count?
⚠ Common exam trap
SC-200 often tests the difference between row-level operations (project, extend) and aggregation operations (summarize), so candidates may incorrectly choose extend or project when asked to count events.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
summarize count() by SourceIp, DestinationIp
The `summarize` operator is the KQL aggregation function that groups rows by one or more columns and computes aggregate values such as `count()`, `sum()`, `avg()`, etc. In this scenario, `summarize count() by SourceIp, DestinationIp` produces a row per unique SourceIp/DestinationIp pair with the number of outbound connection events, which can then be filtered with a `where` clause (e.g., `where Count > 10`) to trigger the Sentinel scheduled query rule. This directly satisfies the requirement to count connections within the 5-minute rule window.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
project SourceIp, DestinationIp
Why it's wrong here
project selects and reorders existing columns; it performs no aggregation, so no count is produced. The rule needs a summarise count() grouped by source IP within a five-minute bin. project is correct when trimming output columns before display or a downstream join.
- ✗
extend Count = 1
Why it's wrong here
extend adds a calculated column to each row, giving every event a literal value of 1 rather than a tally. summarise count() is required to aggregate those rows per source IP over five-minute bins. extend suits deriving per-row fields, such as parsing a severity value.
- ✓
summarize count() by SourceIp, DestinationIp
Why this is correct
`summarize count() by SourceIp, DestinationIp` aggregates events into per-source and per-destination groups, satisfying the stem's requirement to count outbound connections to a known bad IP. Grouping by DestinationIp lets you filter or threshold on that specific address, while the 5-minute window is applied by the scheduled query rule's frequency and lookback settings.
- ✗
join kind=inner (Syslog)
Why it's wrong here
join correlates rows across tables on matching keys; it cannot aggregate a count. The requirement is a per-source-IP tally over a five-minute bin, which summarise with count() provides. join would be right for enriching firewall events with data from another table, such as threat intelligence.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.