SC-200 Perform threat hunting • Set 4
SC-200 Perform threat hunting Practice Test 4 — 15 questions with explanations. Free, no signup.
You are a threat hunter at Fabrikam, a mid-sized company with 2,000 users. Your environment uses: Microsoft 365 E3 licenses; Microsoft Sentinel with the Microsoft 365 Defender connector; Microsoft Defender for Office 365; and Microsoft Defender for Endpoint (without Microsoft Defender for Identity). You are investigating a suspicious email campaign where some users received phishing emails with links to a credential harvesting page. You want to proactively search for any users who may have entered credentials on the phishing page. You have no direct logs from the phishing server. Which hunting approach should you use in Microsoft Sentinel?
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.