Courseiva

SC-200 Respond to security incidents Practice Question

Exhibit

Refer to the exhibit.

```kusto
SecurityAlert
| where TimeGenerated > ago(7d)
| where AlertName == "Malicious SQL injection"
| extend IPAddress = tostring(parse_json(Entities)[0].Address)
| summarize AlertCount = count() by IPAddress
| where AlertCount > 5
| project IPAddress, AlertCount
```

You are investigating repeated SQL injection alerts. The KQL query returns IP addresses with more than 5 alerts in the last 7 days. What is the purpose of the `summarize` and `where AlertCount > 5` lines?

⚠ Common exam trap

Watch out — candidates often confuse `summarize` with `distinct` or think the `where` clause removes duplicates, when in fact the query is designed to surface high-frequency IPs as potential attack sources, not to deduplicate or count unique IPs.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

To identify IPs with a high number of alerts, indicating a possible attack.

The `summarize` operator in KQL aggregates data by grouping on the IP address field and counting the number of alerts per IP. The `where AlertCount > 5` filter then retains only those IP addresses whose aggregated count exceeds 5. This combination directly serves to identify IPs that have triggered a high volume of SQL injection alerts within the 7-day window, which is a strong indicator of a sustained or automated attack attempt.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    To identify IPs with a high number of alerts, indicating a possible attack.

    Why this is correct

    This query aggregates SQL injection alerts by source IP and ranks them by count, so the primary purpose is to surface the IP addresses that trigger the most alert activity. High counts over the selected time range are a strong indicator of an ongoing or repeated attack campaign, and this output directly supports triage, investigation, and potential blocking. The query does not need additional context to fulfill this goal because the aggregation itself is the intended result.

  • ✗

    To correlate alerts with other data sources.

    Why it's wrong here

    The query shown operates only on the SecurityAlert table and performs a simple summarize/count by IP, never joining to other data sources such as CommonSecurityLog, SigninLogs, or ThreatIntelligenceIndicator. Correlation requires a join or lookup to merge alert data with other telemetry, but no such operation appears in the query. Therefore this cannot be the purpose, because the query is syntactically incapable of producing correlated results.

  • ✗

    To remove duplicate alerts from the same IP.

    Why it's wrong here

    Counting alerts per IP does not eliminate duplicate SecurityAlert rows; deduplication requires a distinct operator on a primary key or an explicit summarize by alert identifier before aggregation. The query's group-by IP actually preserves duplicate alerts inside each bucket; it simply compresses them into a total. No mechanism exists in the query to remove or suppress individual records, so this option describes an effect the query does not perform.

  • ✗

    To count the number of distinct IP addresses.

    Why it's wrong here

    The query's count() expression tallies alert records for each IP address, not the number of unique IP addresses in the dataset. To count distinct IPs one would use dcount(IP) or first collect distinct IPs and then count, neither of which is present. Because the output is one row per IP with an alert total, it cannot be interpreted as a measure of unique IP cardinality.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.