SC-200 Manage a security operations environment Practice Question
You manage a Microsoft Sentinel workspace with multiple analytics rules. You notice that an analytics rule has not generated any alerts in the past month despite relevant data being ingested. The rule uses a custom KQL query that joins two tables. What is the most likely cause?
⚠ Common exam trap
Many exam-takers assume the schedule or data connector is the problem, but the key clue is that 'relevant data is being ingested' — this forces you to focus on the query logic, specifically the JOIN condition, as the root cause.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The join condition in the KQL query is incorrect, resulting in no matching records
The most likely cause is an incorrect join condition in the KQL query. When a custom analytics rule uses a JOIN operation between two tables, if the join keys or conditions do not match any records in the ingested data, the query returns zero results, and no alerts are generated. Since the question states that relevant data is being ingested, the issue is not with data availability but with the query logic itself.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The join condition in the KQL query is incorrect, resulting in no matching records
Why this is correct
The join condition in the KQL query is incorrect, which means the query syntactically runs but produces no matching rows. For example, joining on fields with different names, data types, or case values (since KQL joins are case-sensitive) prevents any records from pairing. As a result, the rule's query returns an empty result set each time it executes, so no alerts are created even though both tables contain relevant data.
- ✗
The rule is using an unsupported KQL function
Why it's wrong here
If the rule used an unsupported KQL function, Microsoft Sentinel would fail to validate or execute the query, and the rule's status would show an error in the Analytics rules blade. Unsupported functions cause an explicit failure—not a silent empty result—so the rule would quickly be flagged as broken rather than quietly producing no alerts. Therefore, this does not match the scenario where alerts simply are not generated.
- ✗
The data connector for the tables is disabled
Why it's wrong here
Disabling the data connector for the tables referenced in the query would stop ingestion for those tables entirely, which would affect every analytics rule relying on that data—not just this one rule. Since the scenario implies only this specific rule is failing while other rules presumably continue to run, a disabled connector would create a broader, easily visible data absence in the workspace. Thus, this cause is inconsistent with an isolated loss of alert generation.
- ✗
The rule is running on a schedule of 5 minutes but the data arrives every hour
Why it's wrong here
A 5-minute schedule with hourly data arrival would not prevent alerts; on each 5-minute run, the rule queries whatever data is currently in the workspace, and once the hourly data lands, a subsequent run would include it and trigger the alert correctly. This configuration simply introduces a short delay between data ingestion and detection, not a permanent failure to generate alerts. Therefore, schedule mismatch alone cannot explain the complete absence of alerts.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.