20+ practice questions focused on Perform threat hunting — one of the most tested topics on the Microsoft Security Operations Analyst SC-200 exam. Each question includes a detailed explanation so you learn why the right answer is correct.
Start Perform threat hunting PracticeDuring a threat hunt in Microsoft Sentinel, an analyst creates a custom hunting query that uses the 'externaldata' operator to reference a CSV file stored in Azure Blob Storage. The hunt identifies several suspicious IP addresses that need to be added to a threat intelligence indicator. Which method should the analyst use to persist the findings as indicators of compromise (IOCs) for automated alerting?
Explanation: The Threat Intelligence - Upload Indicators API is the correct method to persist findings as IOCs in Microsoft Sentinel. This API allows you to upload indicators directly to the threat intelligence data store, where they can be used by analytics rules and automation for alerting and response. It is designed for programmatic ingestion of IOCs and integrates with Sentinel's threat intelligence features.
A threat hunter is using Microsoft Sentinel to hunt for signs of privilege escalation via Azure AD role assignment changes. Which TWO KQL operators or functions are most useful for identifying changes that added a user to a high-privilege role?
Explanation: Option D (summarize) is correct because it lets the hunter aggregate Microsoft Entra ID audit events by fields such as the target user, role name, or operation, so they can count or group role-assignment changes and surface suspicious additions to high-privilege roles. Option E (where) is correct because it filters the audit log rows to only those matching the relevant operation, such as 'Add member to role', and to high-privilege role names, isolating the privilege-escalation events of interest. The other options do not belong: project only selects or renames columns and does not identify changes, evaluate runs a subquery or plugin over data rather than filtering role assignments, and mvexpand expands arrays into rows but does not by itself detect or aggregate role-assignment changes.
A threat hunter is investigating a potential data exfiltration via DNS tunneling using Microsoft Defender for Endpoint advanced hunting. Which THREE columns from the DeviceNetworkEvents table should the hunter include in a query to detect anomalous DNS queries?
Explanation: Incorrect for this specific hunting goal. ActionType is a real column in DeviceNetworkEvents (it exists and can be used to filter to DNS-related connection events), but it is not one of the three most useful columns for spotting anomalous DNS tunneling queries — the queried domain (RemoteUrl), timing pattern (Timestamp), and the originating process (InitiatingProcessFileName) are more directly diagnostic of tunneling behavior such as high query volume or unusually long/encoded subdomains.
A security analyst is using Microsoft Sentinel to hunt for signs of a brute-force attack against Azure AD. Which TWO data sources are most relevant for this hunt?
Explanation: SigninLogs (B) is correct because it captures interactive Microsoft Entra ID sign-in events, including failed sign-in attempts, error codes such as 50126 (invalid credentials), and source IP addresses, which are the primary evidence of a brute-force attack against user accounts. AADNonInteractiveUserSignInLogs (E) is correct because it records non-interactive sign-ins (e.g., token refresh, client credential flows), which attackers may also hammer with repeated authentication attempts and which are essential to correlate with interactive failures for a complete brute-force picture. AzureActivity (A) only logs Azure Resource Manager control-plane operations, not authentication events, so it would not show failed sign-ins. OfficeActivity (C) covers Microsoft 365 workload audit events like SharePoint, Exchange, and Teams activities, not Microsoft Entra ID authentication failures. AuditLogs (D) records Microsoft Entra ID directory changes such as user, group, and role modifications, not sign-in attempts, so it is not relevant to detecting brute-force authentication activity.
A threat hunter runs the KQL query above in Microsoft Sentinel to detect accounts that have experienced multiple failed sign-in attempts due to a disabled account (ResultType 50057) from the same IP. The query returns no results even though the hunter knows that some disabled accounts are being attacked. What is the most likely reason for the false negatives?
Explanation: The query uses a time range of only the last hour. If the failed sign-in attempts are spread over a longer period, they will not all be captured within that narrow window, leading to false negatives. Option A is incorrect because ResultType 50057 is indeed the correct code for a disabled account. Option B is incorrect because grouping by both UserPrincipalName and IPAddress is necessary to detect multiple failed attempts from the same IP. Option D is incorrect because the threshold of 5 is likely reasonable; the issue is the time window, not the threshold.
+15 more Perform threat hunting questions available
Practice all Perform threat hunting questions1. Baseline your knowledge
Start with 10 questions to gauge your current understanding of Perform threat hunting. This tells you whether you need a concept refresher or just practice.
2. Review every explanation
For each question — right or wrong — read the full explanation. Understanding why an answer is correct is more valuable than knowing the answer itself.
3. Focus on exam traps
Perform threat hunting questions on the SC-200 frequently use trap wording. Look for subtle differences in answers that test your precision, not just general knowledge.
4. Reach 80% consistently
Do repeated sessions until you score 80%+ three times in a row. Then move to mixed-mode practice to test cross-topic recall under realistic conditions.
The exact number varies per candidate. Perform threat hunting is tested as part of the Microsoft Security Operations Analyst SC-200 blueprint. Practicing with targeted Perform threat hunting questions ensures you can handle any format or difficulty that appears.
Yes. Courseiva provides free SC-200 practice questions across all exam topics and domains. The platform includes topic-based practice, mock exams, missed-question review, bookmarked questions, and readiness tracking — no account required.
Difficulty is subjective, but Perform threat hunting is a high-priority exam concept tested in multiple ways — direct recall, scenario analysis, and command-output interpretation. Consistent practice is the best way to build confidence.
Launch a full Perform threat hunting practice session with instant scoring and detailed explanations.
Start Perform threat hunting Practice →