Courseiva
hardMultiple ChoiceObjective-mapped

SC-200 Practice Question: A global enterprise uses Microsoft 365 Defender…

A global enterprise uses Microsoft 365 Defender across multiple tenants. During an incident, a security analyst needs to search for a specific file hash indicator of compromise (IOC) across all mailboxes and endpoints in all tenants from a single interface. Which feature allows the analyst to run a query across multiple tenants without switching contexts?

⚠ Common exam trap

Test-takers frequently confuse multi-tenant management (a centralized policy and settings tool) with cross-tenant advanced hunting (a query tool), assuming that any 'multi-tenant' feature can run cross-tenant queries, but only cross-tenant advanced hunting supports interactive KQL hunting across tenants.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Cross-tenant advanced hunting

Cross-tenant advanced hunting in Microsoft 365 Defender allows a security analyst to run Kusto Query Language (KQL) queries across multiple tenants from a single interface. This feature is specifically designed for hunting for indicators of compromise (IOCs), such as file hashes, across all mailboxes and endpoints in a multi-tenant environment without requiring the analyst to switch between tenant portals.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Cross-tenant advanced hunting

    Why this is correct

    Cross-tenant advanced hunting in Microsoft 365 Defender provides a native KQL-based query surface that can span multiple tenants at once. A security analyst can search for a specific IOC, such as a SHA256 hash or sender address, across all connected tenants' advanced hunting tables in a single query. This is the only built-in option that supports multi-tenant search on raw telemetry without custom development.

  • Multi-tenant management

    Why it's wrong here

    Multi-tenant management, also referred to as multi-tenant administration, centralizes daily security operations such as incident triage, alert routing, and device posture across tenants in one console. It does not expose a cross-tenant advanced hunting query engine; you cannot write KQL that joins or scans tables from multiple environments. Its purpose is management and visibility, not raw multi-tenant data exploration.

  • Unified audit log

    Why it's wrong here

    The unified audit log in Microsoft Purview is a single per-tenant repository for audit records generated by Exchange, SharePoint, Azure AD, and other Microsoft services. Searches against this log, whether through the compliance portal or via Search-UnifiedAuditLog, operate only within the tenant that owns the log. It does not have a cross-tenant query mode, so an IOC search cannot be executed simultaneously across the enterprise's multiple Microsoft 365 tenants.

  • Microsoft Graph Security API

    Why it's wrong here

    The Microsoft Graph Security API aggregates alerts and incidents from multiple security solutions into a single JSON schema for programmatic consumption, but it does not offer a portal-based, cross-tenant advanced hunting capability. Using it to perform cross-tenant IOC hunting requires you to build a custom application, manage authentication for each tenant, and orchestrate separate queries or load data into a central store. This contrasts with the out-of-the-box cross-tenant hunting experience.

About these practice questions

Courseiva writes every SC-200 question from scratch — 209 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.