SC-200 Manage a security operations environment Practice Question
Exhibit
Refer to the exhibit. ```kusto SecurityAlert | where AlertSeverity == "High" | where TimeGenerated > ago(24h) | summarize AlertCount = count() by AlertName | where AlertCount > 10 | project AlertName, AlertCount ```
You are reviewing the KQL query shown in the exhibit. What is the purpose of this query?
⚠ Common exam trap
It's easy for candidates to confuse `summarize count()` with `summarize count() by bin(TimeGenerated, 1h)` and mistakenly think the query counts alerts per hour, when it actually counts total occurrences per alert name over the entire time range.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Identify high-severity alert names that occurred more than 10 times in the last 24 hours
The query uses `summarize` with `count()` on `AlertName`, then filters with `where count_ > 10`. This groups high-severity alerts by name and returns only those names that appear more than 10 times in the last 24 hours. The `project` statement outputs only the `AlertName` and its count, confirming the purpose is to identify frequently occurring high-severity alert names.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Count the number of high-severity alerts per hour
Why it's wrong here
The query does not use a time-binning function such as `bin()` to group results into hourly buckets. Instead, the `summarize count() by AlertName` operation aggregates counts over the entire 24-hour filter window, so the output is a single count per distinct alert name, not a per-hour breakdown. Hourly aggregation would require an additional `bin(TimeGenerated, 1h)` in the summarize clause, which is absent from the displayed query.
- ✗
Return the timestamp of each high-severity alert
Why it's wrong here
The query's projection and summarization drop the `TimeGenerated` column entirely. The `summarize count() by AlertName` collapses all matching events into aggregated rows, so individual alert timestamps are not available in the result set. Returning timestamps would require projecting `TimeGenerated` and likely using `summarize make_list(TimeGenerated)` or `sort by TimeGenerated`, neither of which appears in the query.
- ✓
Identify high-severity alert names that occurred more than 10 times in the last 24 hours
Why this is correct
This is the correct interpretation because the query explicitly filters for high-severity alerts within the last 24 hours using `where Severity == "High"` and `where TimeGenerated > ago(24h)`, then groups by `AlertName`. The `summarize count() by AlertName` computes the occurrence frequency for each alert name, and the subsequent `where count_ > 10` (or `having count_ > 10`) enforces the threshold. The result is exactly the set of high-severity alert names observed more than 10 times in the specified period.
- ✗
List all high-severity incidents in the last 24 hours
Why it's wrong here
The query is operating on a security alert table, not an incident table. In Microsoft Sentinel, incidents are separate entities that aggregate multiple alerts through correlation rules, whereas this query directly counts raw alert records grouped by their names. Additionally, the output would contain alert names only, not incident identifiers, titles, or severity levels, so it cannot be interpreted as a list of incidents.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.