Courseiva
hardMultiple Choice

SC-200 Practice Question: Arrange the steps in the correct order to create…

Arrange the steps in the correct order to create and save a custom hunting query in Microsoft Sentinel.

⚠ Common exam trap

A common mix-up: candidates confuse the workflow for creating an analytics rule (which involves configuring source, alert grouping, and rule settings) with the simpler, validation-focused process for creating a hunting query, leading them to select options B, C, or D that describe rule creation steps rather than hunting query steps.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Open the Microsoft Sentinel workspace in the Azure portal → Navigate to the Hunting blade in the Sentinel menu → Click on the 'New Query' button → Write the KQL query in the query editor → Run the query to verify results → Save the query with a meaningful name and description

Creating a custom hunting query in Microsoft Sentinel requires first accessing the workspace, then navigating to the Hunting blade, clicking 'New Query', writing the KQL query, running it to validate results, and finally saving it with a meaningful name and description. This sequence ensures the query is tested before being stored, aligning with Sentinel's workflow for ad-hoc threat hunting.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Open the Microsoft Sentinel workspace in the Azure portal → Navigate to the Hunting blade in the Sentinel menu → Click on the 'New Query' button → Write the KQL query in the query editor → Run the query to verify results → Save the query with a meaningful name and description

    Why this is correct

    This sequence is the exact workflow for a Microsoft Sentinel saved hunting query. You must first select the Sentinel workspace, open the Hunting blade, and click 'New Query' to instantiate a blank query editor. Writing and running the KQL before saving is critical because Run executes the query against the workspace's Log Analytics tables and lets you validate the result set. Only after confirming the query returns the intended rows should you save it with a meaningful name and description for future hunting loops.

  • ✗

    Verify results before configuring the source or rule settings.

    Why it's wrong here

    Verification presupposes that a query has been executed and returned data; before you have written any KQL or navigated past the 'New Query' button, there is no result set to evaluate. For a saved hunting query specifically, there are no 'source or rule settings' to configure—the query itself is the artifact, so this option misapplies a configuration concept to an on-demand query workflow. If you attempted to verify first, you would have no query to run against the workspace's Log Analytics tables, making the verification step meaningless.

  • ✗

    Configure alert grouping before defining the detection query or source.

    Why it's wrong here

    Alert grouping is a property of the analytics rule creation wizard (Scheduled or Microsoft Security rule), not of a saved hunting query. In that wizard, you must build the rule logic first—the KQL query and data source—because alert grouping and incident creation settings operate on the results produced by that logic. Configuring grouping first is invalid because the wizard has no schema or result set to attach the group-by fields, such as alert display name, entity mapping, or grouping window, until the query and source are defined.

  • ✗

    Skip validation and enable the rule or plan immediately.

    Why it's wrong here

    Skipping validation in Microsoft Sentinel hunting queries means relying on unrun KQL that may contain syntax errors, reference non-existent tables or functions, or use an incorrect time range, yielding either zero rows or an overwhelming result set. Running the query first catches Kusto Query Language syntax and permission issues and lets you confirm that the results match your hypothesis and intended data source. For an analytics rule, enabling immediately without a test run risks noisy alerts or missed true positives, so the 'Save' or 'Create' action should always follow successful validation.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.