SC-200 Respond to security incidents Practice Question
Exhibit
Refer to the exhibit. ```kql SecurityAlert | where TimeGenerated > ago(1d) | where AlertName contains "ransomware" | summarize count() by AlertName | order by count_ desc ```
You run the above KQL query in Microsoft Sentinel to identify ransomware alerts from the last day. The result shows zero rows. Which is the most likely reason?
⚠ Common exam trap
The SC-200 exam often tests the candidate's ability to distinguish between a query returning zero rows due to a lack of matching data versus a query failing due to syntax or permission errors, leading candidates to incorrectly assume a configuration or permission issue.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
No alerts with 'ransomware' in the name occurred in the last day
The KQL query filters for alerts where the name contains 'ransomware'. If no such alerts were generated in the last day, the query returns zero rows. This is the most likely reason because the query logic is correct, and the absence of data is a valid outcome, not an error.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The table name 'SecurityAlert' is incorrect; it should be 'Alert'
Why it's wrong here
`SecurityAlert` is a legitimate table in Log Analytics workspaces that have Microsoft Sentinel enabled; it stores the normalized alert records generated by analytics rules and connected security products. If the table name were invalid, Kusto would return a 'table not found' semantic error and the query would fail, rather than producing a blank result set. Some environments expose `Alert` from other data sources, but that does not make the `SecurityAlert` reference incorrect for this Sentinel query.
- ✓
No alerts with 'ransomware' in the name occurred in the last day
Why this is correct
The empty result set is a valid query result: within the last 24 hours, no SecurityAlert row had an alert name containing the case-insensitive substring 'ransomware' (assuming a standard `contains` operator). KQL processing filters every row in the time window; when none satisfy the predicate, Kusto returns zero rows without error. This means the query executed successfully and the absence of matching alerts is the most accurate explanation.
- ✗
The user does not have permission to access the SecurityAlert table
Why it's wrong here
If the user lacked permission to read the SecurityAlert table, the query would terminate with an authorization failure (e.g., Log Analytics 'Access denied' or no table access), not an empty table. Sentinel applies workspace-based Access Control (RBAC) per table; a denial prevents any rows from being returned because the layer denies the operator before scanning. Since the query returns no rows rather than an error, the user's role and workspace permissions are sufficient to query the table.
- ✗
The time filter of 1 day is too restrictive; need to increase range
Why it's wrong here
Changing the `ago(1d)` filter to a larger window (e.g., 7d or 30d) would modify the search scope, possibly revealing older ransomware-named alerts, but it does not fix an incorrect query or prove the one-day window is wrong. For a specific query intended to check the last 24 hours, the 1-day range is a standard and valid time boundary; a zero result in that window simply means no new matching alerts were created. If the goal was to investigate a longer period, the query should be intentionally rewritten, but that is a different investigation scope, not a mitigation for an error.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.