SC-200 Perform threat hunting Practice Question
A security analyst is reviewing a threat hunting query in Microsoft Sentinel that uses the Kusto Query Language (KQL) to identify potential lateral movement. The query returns a large number of false positives. What is the most effective way to reduce false positives while maintaining detection coverage?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add allowlist conditions to exclude known administrative tools.
Adding allowlist conditions, such as excluding known administrative tools or approved remote management traffic, directly reduces false positives without removing the core logic. Option A is wrong because increasing the threshold may miss true positives. Option C is wrong because reducing the time range may miss true positives and does not address false positives. Option D is wrong because changing the data source may reduce detection coverage and does not necessarily reduce false positives in the current query.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Increase the threshold for the anomaly score in the query.
Why it's wrong here
Raising the anomaly-score threshold suppresses low-scoring true positives alongside the noise, eroding detection coverage rather than refining which events qualify. It is tempting because it is a single numeric tweak, and would be correct if the query already correlated reliable signals and only borderline scores caused noise.
- ✓
Add allowlist conditions to exclude known administrative tools.
Why this is correct
Allowlisting known administrative tools removes legitimate remote-management activity from the result set, cutting false positives without narrowing the query's scope. Detection coverage for genuine lateral movement persists, since only trusted binaries are excluded rather than whole event categories.
- ✗
Reduce the time range of the query to the last 1 hour.
Why it's wrong here
Shortening the lookback window only hides older events; the same false-positive rate persists within the retained hour, and slow lateral movement may be missed entirely. It is tempting because it reduces result volume quickly, and would be correct when investigating a known recent incident rather than tuning detection logic.
- ✗
Replace the query with a different data source that has less noise.
Why it's wrong here
Swapping data sources abandons the telemetry the detection depends on, so coverage is lost rather than tuned. It appeals because noisy tables do exist, and choosing a quieter source suits building a new analytic from scratch — not refining an existing KQL query, where filtering, joins and thresholds on the same data preserve coverage.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.