Courseiva
hardMultiple Select

SC-200 Practice Question: A SOC analyst needs to create a custom watchlist…

A SOC analyst needs to create a custom watchlist in Microsoft Sentinel to use in an analytics rule. Order the following steps from first to last to correctly create and use the watchlist (Choose 4.)

⚠ Common exam trap

The trap here is that candidates might think the KQL query must be written before importing the CSV, but the watchlist alias must already exist in Sentinel for the _GetWatchlist function to reference it correctly, making the import step second.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

1. Create a new watchlist in Microsoft Sentinel (e.g., from Sentinel > Watchlists > Add new).

Creating a new watchlist in Microsoft Sentinel is the initial step to define a custom data source for threat intelligence or reference data. This is done via Sentinel > Watchlists > Add new, where you specify the alias, description, and other metadata before uploading data. Without this step, there is no container to import the CSV file into, making it the logical first action.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    1. Create a new watchlist in Microsoft Sentinel (e.g., from Sentinel > Watchlists > Add new).

    Why this is correct

    Creating the watchlist in Microsoft Sentinel is the foundational and correct first action because it defines the watchlist's metadata, including a unique alias, name, and optional description, as well as the schema for the data that will be imported. Without this explicit creation step, there is no object for the CSV data to bind to, and the alias cannot be referenced in any later KQL query. In the Sentinel blade, 'Add new' initializes the watchlist resource, and the alias set here is precisely what the _GetWatchlist() function will expect in detection rules.

  • ✓

    2. Import a CSV file containing the data (e.g., IP addresses or domains) into the watchlist.

    Why this is correct

    Importing a CSV file is a necessary second step to populate the watchlist with actual IP addresses, domains, or other indicators, but it cannot occur before the watchlist resource exists. The CSV upload dialog in Sentinel requires a pre-existing watchlist and a defined schema, so selecting this as the creation action ignores that the system has no container to receive the data. Furthermore, the alias from the creation step is already used as a key during import validation, meaning this action inherently depends on the Prior watchlist creation, making it incorrect as the initial step.

  • ✓

    3. Write the KQL query for the analytics rule that uses the `_GetWatchlist('WatchlistAlias')` function to reference the watchlist.

    Why this is correct

    Writing a KQL query that references the watchlist via _GetWatchlist('WatchlistAlias') is a later, detection-authoring activity that assumes the watchlist has been created and populated. This function executes at query time against deployed watchlists, so if the alias does not exist—because creation has not been done—the query will fail or return no rows. Additionally, this step is part of building an analytics rule's logic, which is logically downstream of having the watchlist data ready, and thus it cannot be the correct first action for creating the watchlist itself.

  • ✓

    4. Create a scheduled analytics rule, paste the KQL query, and configure the alert details (e.g., severity, entity mapping).

    Why this is correct

    Creating a scheduled analytics rule to run the KQL query and configuring incident settings is the final operationalization milestone, when the watchlist is woven into automated detection and alerting. This step necessarily presupposes that the watchlist has been created, the CSV has been imported, and the query has been validated; attempting it first would produce a rule whose query references a non-existent watchlist, causing rule creation validation to fail. Moreover, configuring severity, entity mapping, and schedule is about alert response rather than the watchlist's origin, so it is distinct from the initial creation process.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.