SC-200 Manage a security operations environment Practice Question
Exhibit
Refer to the exhibit.
{
"properties": {
"displayName": "MFA Disabled Alert",
"description": "Alert when MFA is disabled for a user.",
"severity": "Medium",
"enabled": true,
"query": "IdentityLogonEvents | where Application == 'Microsoft Entra ID' | where ActionType == 'MFA disabled' | summarize Count=count() by AccountUpn",
"queryFrequency": "PT5H",
"queryPeriod": "PT5H",
"triggerOperator": "GreaterThan",
"triggerThreshold": 0,
"suppressionDuration": "PT5H",
"suppressionEnabled": false
}
}You are reviewing a Microsoft Sentinel analytics rule configuration. The rule is not generating incidents as expected. What is the most likely cause?
⚠ Common exam trap
The trap here is that candidates often focus on query logic or timing parameters, but Microsoft tests the foundational requirement that referenced tables must exist in the workspace for the rule to function at all.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The query references a table that is not available in the Sentinel workspace.
If the query in an analytics rule references a table that does not exist in the Microsoft Sentinel workspace, the rule will fail to execute or return no results, preventing incident generation. This is a common misconfiguration when migrating or authoring rules that depend on specific data connectors or schema that have not been onboarded.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The queryFrequency and queryPeriod are mismatched.
Why it's wrong here
In Sentinel scheduled analytics rules, queryFrequency defines how often the rule runs, while queryPeriod defines how far back the query looks for events. Having both set to 5 hours means the rule runs every 5 hours and searches the previous 5 hours of data, producing a non-overlapping, contiguous window. This is a perfectly valid configuration, so the rule is not defective for this reason.
- ✗
The suppressionDuration is set to 5 hours, suppressing alerts.
Why it's wrong here
The suppressionDuration setting only takes effect when suppressionEnabled is set to true. In this rule, suppression is disabled, so the 5-hour duration is ignored and alerts are generated normally on each scheduled run without being suppressed. Therefore, this option incorrectly describes the rule's behavior.
- ✗
The action type 'MFA disabled' is not supported in IdentityLogonEvents.
Why it's wrong here
IdentityLogonEvents includes a variety of action types related to identity sign-in and authentication, and 'MFA disabled' is one of the recognized ActionType values in that table. The table's schema supports this value, so the query's logic is sound; the actual failure is that the table itself is not populated in the workspace.
- ✓
The query references a table that is not available in the Sentinel workspace.
Why this is correct
IdentityLogonEvents is a table that is only present when the Microsoft Defender for Identity data connector (or Microsoft 365 Defender connector) is enabled and streaming data into the Sentinel workspace. Without that connector, the table does not exist, so the analytics rule query fails with a 'table not found' error when it tries to run. This is the correct explanation for the rule failing.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.