Courseiva

SC-200 Manage a security operations environment Practice Question

Exhibit

Refer to the exhibit.
```kusto
SecurityAlert
| where AlertSeverity == "High"
| where TimeGenerated > ago(24h)
| summarize AlertCount = count() by AlertName
| where AlertCount > 10
| project AlertName, AlertCount
```

You are reviewing the KQL query shown in the exhibit. What is the purpose of this query?

⚠ Common exam trap

It's easy for candidates to confuse `summarize count()` with `summarize count() by bin(TimeGenerated, 1h)` and mistakenly think the query counts alerts per hour, when it actually counts total occurrences per alert name over the entire time range.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Identify high-severity alert names that occurred more than 10 times in the last 24 hours

The query uses `summarize` with `count()` on `AlertName`, then filters with `where count_ > 10`. This groups high-severity alerts by name and returns only those names that appear more than 10 times in the last 24 hours. The `project` statement outputs only the `AlertName` and its count, confirming the purpose is to identify frequently occurring high-severity alert names.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Count the number of high-severity alerts per hour

    Why it's wrong here

    The query does not use a time-binning function such as `bin()` to group results into hourly buckets. Instead, the `summarize count() by AlertName` operation aggregates counts over the entire 24-hour filter window, so the output is a single count per distinct alert name, not a per-hour breakdown. Hourly aggregation would require an additional `bin(TimeGenerated, 1h)` in the summarize clause, which is absent from the displayed query.

  • ✗

    Return the timestamp of each high-severity alert

    Why it's wrong here

    The query's projection and summarization drop the `TimeGenerated` column entirely. The `summarize count() by AlertName` collapses all matching events into aggregated rows, so individual alert timestamps are not available in the result set. Returning timestamps would require projecting `TimeGenerated` and likely using `summarize make_list(TimeGenerated)` or `sort by TimeGenerated`, neither of which appears in the query.

  • ✓

    Identify high-severity alert names that occurred more than 10 times in the last 24 hours

    Why this is correct

    This is the correct interpretation because the query explicitly filters for high-severity alerts within the last 24 hours using `where Severity == "High"` and `where TimeGenerated > ago(24h)`, then groups by `AlertName`. The `summarize count() by AlertName` computes the occurrence frequency for each alert name, and the subsequent `where count_ > 10` (or `having count_ > 10`) enforces the threshold. The result is exactly the set of high-severity alert names observed more than 10 times in the specified period.

  • ✗

    List all high-severity incidents in the last 24 hours

    Why it's wrong here

    The query is operating on a security alert table, not an incident table. In Microsoft Sentinel, incidents are separate entities that aggregate multiple alerts through correlation rules, whereas this query directly counts raw alert records grouped by their names. Additionally, the output would contain alert names only, not incident identifiers, titles, or severity levels, so it cannot be interpreted as a list of incidents.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.