SC-200 Perform threat hunting Practice Question
You are threat hunting in Microsoft Sentinel using KQL. You want to identify potential beaconing activity by looking for regular, periodic network connections from a host. Which KQL operator or function is most appropriate to calculate the time intervals between connections and detect patterns?
⚠ Common exam trap
The trap here is using aggregation functions like bin or make-series that group events into fixed windows, which can mask the precise intervals needed to detect beaconing with jitter.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
serialize then use prev() and datetime_diff()
Detecting beaconing requires analyzing the time intervals between consecutive network connections from a host. The serialize operator orders events, prev() retrieves the previous timestamp, and datetime_diff() calculates the interval. You can then summarize these intervals to find regularity, such as a low standard deviation or a common interval. This method works even with jitter, making it the most effective for identifying command-and-control beaconing patterns.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
serialize then use prev() and datetime_diff()
Why this is correct
To detect beaconing, you need to calculate the time difference between consecutive connections from the same host. The serialize operator orders the rows, and prev() accesses the previous row's timestamp. datetime_diff() then computes the interval. By analyzing these intervals for regularity (e.g., low standard deviation), you can identify beaconing. This approach is flexible and works with irregular intervals, making it the most appropriate for this scenario.
- ✗
make-series count() on TimeGenerated step 1m
Why it's wrong here
make-series creates a series of aggregated values over a specified time step, which can be useful for visualizing trends. However, it aggregates data into fixed intervals and does not compute the actual time differences between individual connection events. Beaconing detection requires analyzing the precise intervals between connections, which may not align with the step size. Thus, make-series is less precise for this purpose than calculating intervals directly.
- ✗
join kind=inner on RemoteIP
Why it's wrong here
A join on RemoteIP would correlate events from different tables or within the same table based on the remote IP, but it does not calculate time intervals between connections. It could help identify multiple hosts connecting to the same IP, but not the periodicity of connections from a single host. For beaconing detection, interval calculation is key, and join does not provide that directly.
- ✗
summarize count() by bin(TimeGenerated, 1m)
Why it's wrong here
Using summarize with bin(TimeGenerated, 1m) aggregates events into one-minute buckets and counts them. While this can show if connections occur every minute, it does not calculate the intervals between individual connections. It would not effectively detect varying but regular intervals, such as every 5 minutes with jitter. It is more suited for volume analysis than for precise interval calculation needed for beaconing detection.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.