SC-200 Manage a security operations environment Practice Question
You are managing a Microsoft Sentinel environment. An analyst reports that a scheduled analytics rule is not generating alerts. The rule has been enabled for a week. What is the most likely cause?
⚠ Common exam trap
It's easy for candidates to assume a rule is disabled or misconfigured due to cost or timing, but the core issue is almost always that the query itself does not match any data, which is the most straightforward and common cause for a rule not generating alerts.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The rule's query does not match any events in the workspace.
The most likely cause is that the rule's query does not match any events in the workspace. Since the rule has been enabled for a week, if the query logic is correct and data exists, alerts should have been generated. The absence of alerts strongly indicates that the query returns zero results, which is a common issue when the KQL query references tables, columns, or conditions that do not exist in the ingested data.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The rule is disabled due to a cost threshold.
Why it's wrong here
In Microsoft Sentinel, there is no built-in cost threshold that automatically disables analytics rules. Cost management features control data ingestion and retention, but they do not toggle the status of a scheduled alert rule. A rule appears disabled only through explicit user action, an API request, or a policy, not because of spending limits.
- ✗
The rule has a short lookback period that misses data.
Why it's wrong here
A short lookback period would limit how far back the query searches, but the rule has been running for a week and would still catch any events that occurred within each execution window. The lookback affects the time range, not whether events are present; if matching data existed, the rule would have generated an alert regardless of lookback duration. The absence of alerts points to the query itself returning no results, not to a time-window issue.
- ✓
The rule's query does not match any events in the workspace.
Why this is correct
A scheduled analytics rule only raises an alert when its KQL query returns one or more rows. If the query's conditions, such as event type, severity, or threshold, do not match any ingested data, the rule runs successfully but remains silent. Since it has been running for a week, the most probable reason for zero alerts is that no events satisfy the query. Test the query manually in Log Analytics over the same lookback period to confirm.
- ✗
The rule is configured as a real-time rule instead of scheduled.
Why it's wrong here
Configuring a rule as a near-real-time (NRT) rule instead of a standard scheduled rule does not suppress alerts; NRT rules still evaluate queries every few minutes and create incidents when results are returned. Both rule types rely on query results, so switching types would not stop alerts if conditions are met. The real-time nature changes only the frequency of evaluation, not the requirement for matching events.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.