Courseiva
Perform threat hunting →easyMultiple Choice

SC-200 Perform threat hunting Practice Question

As a threat hunter, you want to use MITRE ATT&CK techniques to categorize detected behaviors. In Microsoft Sentinel, which feature allows you to map alerts to MITRE techniques automatically?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Analytics rules

Analytics rules in Microsoft Sentinel allow you to map alerts to MITRE ATT&CK techniques automatically. When creating or editing an analytics rule, you can select the relevant MITRE ATT&CK tactic and technique, which enriches the alert with threat intelligence context. Workbooks (Option D) are for visualization, not mapping. Playbooks (Option B) are for automated response. Watchlists (Option C) are for reference data. Therefore, Option A is correct.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Analytics rules

    Why this is correct

    Analytics rules in Microsoft Sentinel include a MITRE ATT&CK mapping section where each rule's tactics and techniques are configured. When the rule fires, generated incidents and alerts inherit those technique tags automatically, satisfying the requirement to categorise detected behaviours without manual enrichment.

  • ✗

    Playbooks

    Why it's wrong here

    Playbooks are Logic Apps workflows that run automated response actions after an alert fires; they execute remediation, they do not attach MITRE technique metadata to detections. They are tempting because they are triggered by alerts, but technique tagging happens in the analytics rule definition, before any playbook runs.

  • ✗

    Watchlists

    Why it's wrong here

    Watchlists are imported CSV tables used to correlate events against known entities such as IPs or VIP users; they store lookup data, not MITRE technique mappings. They are tempting because they enrich alerts, but the automatic ATT&CK tagging is configured on the analytics rule itself, not in a watchlist.

  • ✗

    Workbooks

    Why it's wrong here

    Workbooks render dashboards and visual reports from Log Analytics queries; they hold no mapping engine that tags alerts with MITRE technique IDs. They are tempting because hunting results are often visualised there, but the automatic technique mapping lives in the analytics rule's entity and alert configuration, not in a workbook.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.