SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
Exhibit
KQL query: SecurityAlert | where TimeGenerated > ago(7d) | where AlertName has "MFA" or AlertName has "Suspicious sign-in" | extend UserPrincipalName = tostring(Entities[0].AccountUpn) | summarize Count = count() by UserPrincipalName, AlertName | where Count > 3
Refer to the exhibit. A security analyst in your SOC runs the provided KQL query in Microsoft Sentinel to identify users with repeated MFA or suspicious sign-in alerts. The query returns no results even though alerts exist. What is the most likely issue?
⚠ Common exam trap
The trap is assuming the query logic is broken (e.g., case sensitivity or time filter) when the real issue is that the alert names simply do not contain the searched substrings, a data-mismatch problem rather than a syntax problem.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The alert names do not contain the strings 'MFA' or 'Suspicious sign-in'.
The KQL query filters SecurityAlert records using 'where AlertName has "MFA" or AlertName has "Suspicious sign-in"'. If the actual alert names in Microsoft Sentinel do not contain those exact substrings, the filter returns zero rows even though alerts exist. The most likely issue is therefore that the alert names do not match the strings used in the query.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The 'extend' operator fails because 'Entities' array is empty.
Why it's wrong here
The 'extend' operator in KQL is designed to add new columns to the result set and does not fail if the source data for the new column is empty or null. If the 'Entities' array were empty for some alerts, the 'extend' operation would simply result in a null or empty array for the 'AccountUpn' column for those specific rows. This behavior allows the query to continue executing without error, even if it might produce empty values for the extended column.
- ✓
The alert names do not contain the strings 'MFA' or 'Suspicious sign-in'.
Why this is correct
This is the most plausible reason for no results. The query specifically filters for `AlertName has 'MFA'` or `AlertName has 'Suspicious sign-in'`. If the actual alert names in the system use slightly different terminology, such as "Microsoft Entra ID MFA Activity" or "Unusual Sign-in Attempt," they would not contain the exact substrings specified and thus would not be returned by the query. The absence of results strongly suggests a mismatch between the queried strings and the actual alert naming conventions.
- ✗
The TimeGenerated filter is too restrictive; alerts older than 7 days are excluded.
Why it's wrong here
A TimeGenerated filter of ago(7d) is a standard and generally reasonable timeframe for investigating recent security alerts. If the query returns no results, it implies that *no* alerts matching the criteria were generated within the last seven days, not necessarily that the filter is inherently too restrictive. For a typical active environment, a 7-day window should capture relevant recent events, making it unlikely to be the sole reason for a complete absence of results.
- ✗
The 'has' operator is case-sensitive and the alert names are in uppercase.
Why it's wrong here
The 'has' operator in Kusto Query Language (KQL) is inherently case-insensitive by default when performing string searches. Therefore, even if the alert names were entirely in uppercase (e.g., "MFA SUSPICIOUS SIGN-IN"), the query `AlertName has 'MFA' or AlertName has 'Suspicious sign-in'` would still successfully match those strings. The case of the alert names or the search terms is not a factor preventing results.
Go deeper
Related to this question
Learn chapter
SAML and Single Sign-On (SSO)
Key term
Alert
An alert is a notification that something unusual or potentially harmful has happened in a computer system or network.
Key term
Microsoft Sentinel
Microsoft Sentinel is a cloud-native security information and event management (SIEM) and security orchestration automation and response (SOAR) service that helps organizations detect, investigate, and respond to cyber threats across their entire digital estate.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,279 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.