Which background query tool fits a requirement, compared by data source, joins, schedule, lookback, timeout and result limits.
From Ultra Transcenders SC-200 by Tony Rough (coming November 2026)
All three run queries in the background and write results to a table, so the exam tests which one fits a requirement. Microsoft’s comparison: Figure 12.1 sets the three side by side.
| Feature | KQL jobs | Summary rules | Search jobs |
|---|---|---|---|
| Needs data lake onboarding | Yes | No | No |
| Source data | Data lake tier | Analytics, Auxiliary, Basic, data lake | Analytics, data lake; Auxiliary, Basic and archived for workspaces not on the data lake |
| Tables | Multiple | Multiple | Single |
| Federated tables | Yes | No | No |
| Joins | Supported | Analytics: yes; Basic: lookup to up to five Analytics tables |
Not supported |
| Schedule | On demand or scheduled | 20 minutes to 24 hours | On demand |
| Lookback | Up to 12 years | Up to 1 day | Up to 12 years (timespan up to 1 year) |
| Timeout | 1 hour | 10 minutes | 24 hours |
| Maximum results | Bound by the timeout | 500,000 records | 100 million records |
| Pricing | GB analysed | Free for Analytics sources; data scan for Basic and Auxiliary | GB analysed |
| Templates and health monitoring | No | Templates (Content hub, ARM); LASummaryLogs | No |
Quick decision rules:
| Requirement | Use |
|---|---|
| Query years of history with joins or unions across several tables | KQL job |
| Promote a filtered subset of lake data to the analytics tier on a schedule | KQL job |
| Aggregate verbose logs every 20 minutes into a small Analytics table for rules and workbooks | Summary rule |
| Workspace not onboarded to the data lake, data in Basic or Auxiliary tables, frequent summarisation | Summary rule |
| Pull matching records from one huge table, or from archive-tier data | Search job |
| Data from before your data lake onboarding date | Search job (KQL jobs cover data from the onboarding date onward) |
On KQL jobs, the comparison table lists daily, weekly and monthly schedules and no template support, while the KQL jobs article also offers by-minute and hourly repeat frequencies and built-in job templates.
Common trap: Choosing a search job to correlate two tables - search jobs work on one table and don’t support joins; use a KQL job (data lake) or restore the data and query it.
This note is one section of Ultra Transcenders SC-200: Microsoft Security Operations Analyst, an independent study guide that explains every topic the exam covers by technology, with comparison tables, diagrams and the common traps, plus a glossary linked to Microsoft Learn.
Due on Amazon in November 2026, in Kindle and paperback editions.
About the book · SC-200 terms in the glossary · All SC-200 study notes
How Defender XDR custom detections, scheduled, NRT, threat intelligence, Fusion, ML and anomaly rules differ, and the capability gaps that still decide between them.
How the two Azure Monitor Agent connectors differ, how a Linux log forwarder is set up, and how to avoid ingesting the same messages twice.
What ASR rules need to run, the difference between Audit, Warn, Block, Disabled and Not configured, and which deployment methods support per-rule exclusions.
The full and semi-automated remediation levels set per device group, how pending actions expire, and what automation folder exclusions do and don't affect.
The three advanced feature toggles, basic versus advanced live response permissions, the key commands and the session and file size limits.
Which email protection and investigation tools each plan includes, with the Safe Attachments responses, impersonation settings and zero-hour auto purge actions.
How the two risk types and their detections work, where to see them, and how risk-based Conditional Access now replaces the retired legacy risk policies.