SC-200 Perform threat hunting Practice Question
A threat hunter wants to correlate alerts from multiple Microsoft security products in Microsoft Sentinel. Which feature should be used to create a unified incident?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Analytics Rules
Analytics Rules in Microsoft Sentinel can be configured to create incidents from alerts across multiple security products, enabling unified incident creation for threat hunting. Option A (Threat Intelligence) is used to import and use threat intelligence feeds, not to create incidents. Option B (Jupyter Notebooks) provides a platform for security analysis and automation using Python, not for incident creation. Option D (Investigation Graph) is a visual tool for exploring connections between entities in an investigation, not for creating incidents.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Threat Intelligence
Why it's wrong here
Threat Intelligence in Sentinel refers to the import and management of indicators of compromise (IOCs) such as malicious IPs, domains, URLs, and hashes. While analytics rules can match incoming alerts against threat intelligence indicators to detect threats, the Threat Intelligence feature itself does not create or correlate incidents; it only supplies data for detection. Its role is passive enrichment, not active alert correlation or incident creation.
- ✗
Jupyter Notebooks
Why it's wrong here
Jupyter Notebooks are interactive Python environments within Microsoft Sentinel that support advanced threat hunting through custom queries, data visualization, and MSTICpy integrations. Despite their power for ad-hoc analysis and machine learning, notebooks do not have native functionality to persist alerts as incidents or correlate alerts across product sources. Incident correlation is a rule-based process, not an interactive notebook action.
- ✓
Analytics Rules
Why this is correct
Analytics Rules (also called scheduled or incident creation rules) are the correct mechanism in Microsoft Sentinel for correlating alerts from multiple security products into a unified incident. These rules are built on Kusto Query Language (KQL) and can use entity mapping and alert grouping to combine multiple separate alerts—whether from Microsoft Defender, Azure, or third-party connectors—into one incident based on common entities and a defined time window. When a query returns results and incident creation is enabled, Sentinel creates an incident enriched with the matching alerts, which is exactly what a threat hunter needs for correlation.
- ✗
Investigation Graph
Why it's wrong here
The Investigation Graph is a visual tool in Sentinel that displays entities (e.g., hosts, accounts, IPs) and their relationships for a single alert or incident. It helps an analyst manually explore and understand the blast radius of a suspected threat, but it is purely reactive and does not ingest or correlate alerts from multiple sources to generate new incidents automatically. Creating an incident requires an analytics rule trigger, not a graph visualization.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.