Courseiva

SC-200 Respond to security incidents Practice Question

Exhibit

Refer to the exhibit.
```kql
SecurityAlert
| where TimeGenerated > ago(1d)
| where AlertName contains "ransomware"
| summarize count() by AlertName
| order by count_ desc
```

You run the above KQL query in Microsoft Sentinel to identify ransomware alerts from the last day. The result shows zero rows. Which is the most likely reason?

⚠ Common exam trap

The SC-200 exam often tests the candidate's ability to distinguish between a query returning zero rows due to a lack of matching data versus a query failing due to syntax or permission errors, leading candidates to incorrectly assume a configuration or permission issue.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

No alerts with 'ransomware' in the name occurred in the last day

The KQL query filters for alerts where the name contains 'ransomware'. If no such alerts were generated in the last day, the query returns zero rows. This is the most likely reason because the query logic is correct, and the absence of data is a valid outcome, not an error.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The table name 'SecurityAlert' is incorrect; it should be 'Alert'

    Why it's wrong here

    `SecurityAlert` is a legitimate table in Log Analytics workspaces that have Microsoft Sentinel enabled; it stores the normalized alert records generated by analytics rules and connected security products. If the table name were invalid, Kusto would return a 'table not found' semantic error and the query would fail, rather than producing a blank result set. Some environments expose `Alert` from other data sources, but that does not make the `SecurityAlert` reference incorrect for this Sentinel query.

  • ✓

    No alerts with 'ransomware' in the name occurred in the last day

    Why this is correct

    The empty result set is a valid query result: within the last 24 hours, no SecurityAlert row had an alert name containing the case-insensitive substring 'ransomware' (assuming a standard `contains` operator). KQL processing filters every row in the time window; when none satisfy the predicate, Kusto returns zero rows without error. This means the query executed successfully and the absence of matching alerts is the most accurate explanation.

  • ✗

    The user does not have permission to access the SecurityAlert table

    Why it's wrong here

    If the user lacked permission to read the SecurityAlert table, the query would terminate with an authorization failure (e.g., Log Analytics 'Access denied' or no table access), not an empty table. Sentinel applies workspace-based Access Control (RBAC) per table; a denial prevents any rows from being returned because the layer denies the operator before scanning. Since the query returns no rows rather than an error, the user's role and workspace permissions are sufficient to query the table.

  • ✗

    The time filter of 1 day is too restrictive; need to increase range

    Why it's wrong here

    Changing the `ago(1d)` filter to a larger window (e.g., 7d or 30d) would modify the search scope, possibly revealing older ransomware-named alerts, but it does not fix an incorrect query or prove the one-day window is wrong. For a specific query intended to check the last 24 hours, the 1-day range is a standard and valid time boundary; a zero result in that window simply means no new matching alerts were created. If the goal was to investigate a longer period, the query should be intentionally rewritten, but that is a different investigation scope, not a mitigation for an error.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.