SC-200 Perform threat hunting Practice Question
You need to create a custom detection rule in Microsoft Sentinel that alerts when an anomalous number of failed logons occur from a single IP address within 5 minutes. Which KQL operator should you use to count failed logons per IP?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
summarize
'summarize' is used to aggregate counts per key (IP). Option B (project) only selects columns. Option C (where) filters rows. Option D (extend) adds calculated columns.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
summarize
Why this is correct
The summarize operator aggregates log data, allowing you to count failed logons grouped by IP address within a five-minute bin. This produces the per-IP threshold needed to trigger the anomalous failed-logon alert in Microsoft Sentinel.
- ✗
project
Why it's wrong here
project selects and renames columns; it neither groups records nor aggregates them, so it cannot produce a per-IP failed-logon count. It is tempting because it shapes the output columns, and would be correct when trimming a result set to specific fields before display or further processing.
- ✗
where
Why it's wrong here
where filters rows against a predicate but performs no grouping or aggregation, so it cannot count failed logons per IP address. It is tempting because it narrows the dataset to failed events, and would be correct as a filtering step feeding a summarise that does the counting.
- ✗
extend
Why it's wrong here
extend adds calculated columns to each row; it does not group rows or count them, so no per-IP tally results. It is tempting because it creates derived fields, and would be correct when enriching events with computed values such as a parsed hostname or severity before filtering.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.