Courseiva
Perform threat hunting →mediumMultiple Choice

SC-200 summarize Practice Question

You are a threat hunter using Microsoft Sentinel. You have ingested syslog data from a Palo Alto firewall. You want to create a scheduled query rule that alerts when more than 10 outbound connections to a known bad IP address occur within 5 minutes. Which KQL function should you use to summarize the count?

⚠ Common exam trap

SC-200 often tests the difference between row-level operations (project, extend) and aggregation operations (summarize), so candidates may incorrectly choose extend or project when asked to count events.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

summarize count() by SourceIp, DestinationIp

The `summarize` operator is the KQL aggregation function that groups rows by one or more columns and computes aggregate values such as `count()`, `sum()`, `avg()`, etc. In this scenario, `summarize count() by SourceIp, DestinationIp` produces a row per unique SourceIp/DestinationIp pair with the number of outbound connection events, which can then be filtered with a `where` clause (e.g., `where Count > 10`) to trigger the Sentinel scheduled query rule. This directly satisfies the requirement to count connections within the 5-minute rule window.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    project SourceIp, DestinationIp

    Why it's wrong here

    project selects and reorders existing columns; it performs no aggregation, so no count is produced. The rule needs a summarise count() grouped by source IP within a five-minute bin. project is correct when trimming output columns before display or a downstream join.

  • ✗

    extend Count = 1

    Why it's wrong here

    extend adds a calculated column to each row, giving every event a literal value of 1 rather than a tally. summarise count() is required to aggregate those rows per source IP over five-minute bins. extend suits deriving per-row fields, such as parsing a severity value.

  • ✓

    summarize count() by SourceIp, DestinationIp

    Why this is correct

    `summarize count() by SourceIp, DestinationIp` aggregates events into per-source and per-destination groups, satisfying the stem's requirement to count outbound connections to a known bad IP. Grouping by DestinationIp lets you filter or threshold on that specific address, while the 5-minute window is applied by the scheduled query rule's frequency and lookback settings.

  • ✗

    join kind=inner (Syslog)

    Why it's wrong here

    join correlates rows across tables on matching keys; it cannot aggregate a count. The requirement is a per-source-IP tally over a five-minute bin, which summarise with count() provides. join would be right for enriching firewall events with data from another table, such as threat intelligence.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.