Courseiva

SC-200 Respond to security incidents Practice Question

You are investigating a ransomware incident in Microsoft Sentinel. The incident contains multiple alerts from Microsoft Defender for Endpoint, Microsoft Defender for Office 365, and Microsoft Defender for Identity. You need to correlate the alerts and identify the initial entry point. Which KQL function should you use to combine the alerts?

⚠ Common exam trap

A common mix-up: candidates confuse `union` (which simply appends rows) with the need to correlate alerts by a common entity, leading them to overlook `make_set()` as the correct aggregation function for grouping distinct alert data from multiple sources.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

make_set()

D is correct because `make_set()` is used with `summarize` to create a distinct list of values from a column across multiple rows, which is essential for correlating alerts from different data sources (e.g., DeviceEvents, EmailEvents, IdentityLogonEvents) by a common identifier like `DeviceName` or `AccountUpn`. This allows you to group alerts from Defender for Endpoint, Office 365, and Identity into a single row per entity, making it easier to trace the initial entry point by analyzing the timeline of distinct alert types.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    materialize()

    Why it's wrong here

    materialize() is a KQL function that caches a subquery result in memory so that downstream references can reuse the computed rows without re-executing the query. It does not aggregate or combine values; instead, it returns the exact same rows as the original query, merely stored temporarily. In a ransomware investigation, you might use materialize() to optimize a repeated reference to a filtered alert table, but it cannot collect or correlate alert titles into a single array. Therefore, it is not suitable for the required alert correlation.

  • ✗

    union

    Why it's wrong here

    union is a KQL operator that merges multiple tables or query results by concatenating their rows vertically into a single result set. This is useful when you need to combine alerts from different data sources, such as SecurityEvent and SecurityAlert, but it does not group or aggregate rows within the same table. Correlating alert titles for a single entity or time window requires a summarize operation, not simple row stacking. Thus, union is not appropriate for generating a combined array of alert titles from one alert table.

  • ✗

    mv-expand

    Why it's wrong here

    mv-expand is a KQL operator that expands multi-value properties, such as dynamic arrays, into individual rows, effectively performing the opposite of aggregation. It is typically used to flatten fields like a list of processes or IP addresses into a normalized tabular structure for analysis. When investigating ransomware, you might use mv-expand to break apart a packed alert property, but it will not group alert titles or build a correlation array. Hence, it is unrelated to the aggregation needed to combine alert titles for incident correlation.

  • ✓

    make_set()

    Why this is correct

    make_set() is a KQL aggregation function that constructs an array of unique values from a specified column, grouped by one or more key columns. When correlating alerts in a ransomware investigation, you can use make_set(AlertTitle) with a summarize by Account or Hostname to gather all distinct alert names that fired for that entity. This creates a concise, ordered set of alert titles that reveals the sequence or combination of malicious activities, such as initial access and data encryption. It is therefore the correct choice for aggregating alert titles to support correlation analysis.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.