Courseiva
mediumDrag & Drop

SC-200 Practice Question: Arrange the steps to run a Microsoft 365 Defender…

Arrange the steps to run a Microsoft 365 Defender advanced hunting query and create a custom detection rule from it.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Step 1: Navigate to Advanced hunting in Microsoft 365 Defender. Step 2: Write a KQL query. Step 3: Run the query. Step 4: Create a custom detection rule from the query results.

After running a query in Advanced hunting, you can create a detection rule directly from the results to alert on future matches.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Step 1: Navigate to Advanced hunting in Microsoft 365 Defender. Step 2: Write a KQL query. Step 3: Run the query. Step 4: Create a custom detection rule from the query results.

    Why this is correct

    This sequence is correct because Advanced hunting is a module within Microsoft 365 Defender that you must open before you can author a query. Once in the Advanced hunting page, the KQL query editor is available, and you write your query in that editor. Only after the query is written can you run it to retrieve results. Finally, after examining the returned events, you can select 'Create detection rule' to turn that query into a custom detection rule that runs on a schedule and generates alerts.

  • ✗

    Step 1: Write a KQL query. Step 2: Navigate to Advanced hunting in Microsoft 365 Defender. Step 3: Run the query. Step 4: Create a custom detection rule from the query results.

    Why it's wrong here

    This order is incorrect because you cannot write a KQL query before opening the Advanced hunting interface—the query editor is only accessible inside the Advanced hunting page in the Microsoft 365 Defender portal. If you attempted to 'write a query' first, you would have nowhere to enter the KQL, and the subsequent navigation step would not retroactively validate or execute that unwritten query. The correct workflow requires opening the hunting module first to gain access to the editor, then composing the query, then running it.

  • ✗

    Step 1: Navigate to Advanced hunting in Microsoft 365 Defender. Step 2: Run the query. Step 3: Write a KQL query. Step 4: Create a custom detection rule from the query results.

    Why it's wrong here

    This sequence is invalid because you cannot run a query before the KQL text has been written; the 'Run query' button in Advanced hunting is disabled until there is a non-empty query in the editor. Attempting to run a query first would simply execute a blank query, which returns no meaningful results and cannot lead to a custom detection rule. Writing the KQL must precede execution because the query is the instruction set that the hunting engine interprets to fetch data.

  • ✗

    Step 1: Navigate to Advanced hunting in Microsoft 365 Defender. Step 2: Write a KQL query. Step 3: Create a custom detection rule from the query results. Step 4: Run the query.

    Why it's wrong here

    This ordering is wrong because a custom detection rule is derived from the results returned by an executed query, so running the query must happen before any rule creation. In the Advanced hunting UI, the 'Create detection rule' option only becomes meaningful after you have run the query and reviewed the output—you cannot base a rule on data you have not yet retrieved. Placing rule creation before running the query breaks the dependency between the query results and the detection rule’s logic.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.