SC-200 › Perform threat hunting
This domain covers proactive threat hunting across Microsoft Sentinel, Defender XDR, and Defender for Cloud. You are tested on choosing the right data source or table, pivoting between entities like IPs, accounts, and devices, and recognizing KQL query limitations when correlating multi-stage attacker activity.
SC-200 Perform threat hunting — All 295 Questions
Every question in this domain with answers and detailed explanations.