SC-100 Practice Question: Design security operations, identity, and compliance capabilities
Your organization uses Microsoft Sentinel and wants to improve threat hunting efficiency. Which THREE actions should you take?
⚠ Common exam trap
Many candidates confuse passive data enrichment tools (like watchlists) with active hunting techniques, or mistakenly think reducing data retention improves security operations, when in fact it hinders long-term threat detection and forensic analysis.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable UEBA (User and Entity Behavior Analytics)
UEBA (User and Entity Behavior Analytics) in Microsoft Sentinel uses machine learning models to establish baseline behavioral patterns for users, hosts, and other entities. It then detects anomalous activities such as unusual logon times, impossible travel, or abnormal data exfiltration, which directly enhances threat hunting by surfacing suspicious behaviors that might otherwise go unnoticed.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enable UEBA (User and Entity Behavior Analytics)
Why this is correct
Enabling UEBA in Microsoft Sentinel gives threat hunters behavioral baselines for users, hosts, and applications. By leveraging machine learning to detect anomalies such as unusual sign-in patterns or lateral movement, UEBA surfaces high-fidelity leads. This enriches entities in hunting queries with risk scores and behavioral insights, making detection of insider threats or compromised accounts far more effective.
- ✓
Integrate Microsoft Defender XDR for cross-domain hunting
Why this is correct
Integrating Microsoft Defender XDR provides a unified telemetry stream from endpoints, email, identities, and cloud apps into Sentinel's hunting workspace. This cross-domain data lets hunters correlate signals across the entire kill chain, such as linking a phishing email to a later device compromise. Without this integration, hunters only see logs ingested into Sentinel and may miss the full attack story.
- ✓
Create custom hunting queries using KQL
Why this is correct
Custom hunting queries written in KQL allow analysts to test hypotheses and search for specific IoCs, TTPs, and unusual time-series patterns directly in actual log data. KQL's rich operators, such as join, make, and timechart, enable sophisticated, targeted hunting that cannot be achieved with out-of-the-box analytics. This proactive approach helps uncover stealthy or novel threats that automated rules fail to flag.
- ✗
Use watchlists to filter out known benign IPs
Why it's wrong here
Watchlists in Sentinel are designed to join and correlate query results with external lists of indicators, not to preemptively filter data out of hunting. Using a watchlist to filter out known benign IPs would actually reduce visibility, because attackers can spoof or compromise these IPs, and hiding them would obscure malicious activity. Moreover, watchlists only operate during query execution and do not improve initial log collection or hunting performance.
- ✗
Reduce data retention period to improve query speed
Why it's wrong here
Reducing the data retention period deletes and shortens the availability of historical logs, directly shrinking the hunting surface for investigating compromises over time. While lower data volume may improve query speed, it sacrifices the ability to perform retrospective searches and forensics, which is central to threat hunting. Instead, query speed should be optimized via proper KQL syntax, indexing strategies, and workspace scaling rather than discarding evidence.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.