SC-200 Manage a security operations environment Practice Question
Your organization is using Microsoft Sentinel and has deployed the Microsoft Entra ID (Azure AD) connector. You need to create an analytics rule that triggers an incident when a user from a specific IP address is assigned the Global Administrator role. The IP address is not in your trusted IP list. Which KQL query should you use as the rule logic?
⚠ Common exam trap
A common mix-up: candidates confuse the `!has` operator (which checks for substring containment) with the `!in` operator (which checks for exact membership in a list), leading them to select Option C which would incorrectly exclude entire IP subnets rather than specific trusted IPs.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AuditLogs | where ActivityDisplayName == 'Add member to role' and TargetResources[0].displayName == 'Global Administrator' and InitiatedBy.app.ipAddress !in (dynamic(['10.0.0.1', '10.0.0.2']))
It uses the `!in` operator to filter out specific IP addresses from the `InitiatedBy.app.ipAddress` field, ensuring that only events from IP addresses not in the trusted list trigger an incident. The query correctly targets `AuditLogs` with `ActivityDisplayName == 'Add member to role'` and checks that the role assigned is `Global Administrator` via `TargetResources[0].displayName`. This logic matches the requirement to alert when a user from a specific IP address (10.0.0.1) that is not in the trusted list is assigned the Global Administrator role.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AuditLogs | where ActivityDisplayName == 'Add member to role' and TargetResources[0].displayName == 'Global Administrator' and InitiatedBy.app.ipAddress == '10.0.0.1'
Why it's wrong here
This query uses the equality operator (==) against a single hard-coded IP address, so it will only match events where InitiatedBy.app.ipAddress is exactly '10.0.0.1'. It fails to exclude the full set of trusted IPs, and because it is an equality filter it will actually return rather than suppress the trusted IP's activity, making it the inverse of the intended alert logic.
- ✓
AuditLogs | where ActivityDisplayName == 'Add member to role' and TargetResources[0].displayName == 'Global Administrator' and InitiatedBy.app.ipAddress !in (dynamic(['10.0.0.1', '10.0.0.2']))
Why this is correct
This is correct because it uses the !in operator with a dynamic array literal containing the trusted IP addresses, which properly excludes any events initiated from either 10.0.0.1 or 10.0.0.2 while still capturing all other IPs performing Global Administrator role assignments. The dynamic array syntax is the proper KQL way to represent a list of values for membership testing.
- ✗
AuditLogs | where ActivityDisplayName == 'Add member to role' and TargetResources[0].displayName == 'Global Administrator' and InitiatedBy.app.ipAddress !has '10.0.'
Why it's wrong here
The !has operator performs a case-insensitive substring search on the string representation of the IP, so '10.0.' will match any IP containing that substring (e.g., 10.0.1.5, 210.0.10.1), not just the trusted addresses. It also doesn't reference the actual trusted IP list, leaving gaps and potentially missing exclusions or over-excluding non-malicious traffic.
- ✗
AuditLogs | where ActivityDisplayName == 'Add member to role' and TargetResources[0].displayName == 'Global Administrator' and InitiatedBy.app.ipAddress !in ('trusted IP list')
Why it's wrong here
The syntax !in ('trusted IP list') is invalid because the right side of the !in operator must be a tabular expression, a scalar expression, or a dynamic array, not a plain string literal. Even if it were syntactically corrected, passing the literal text 'trusted IP list' would compare against that exact string, not the actual trusted IPs, so it would fail to exclude anything.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.