SC-200 Perform threat hunting Practice Question
As a threat hunter, you want to use MITRE ATT&CK techniques to categorize detected behaviors. In Microsoft Sentinel, which feature allows you to map alerts to MITRE techniques automatically?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Analytics rules
Analytics rules in Microsoft Sentinel allow you to map alerts to MITRE ATT&CK techniques automatically. When creating or editing an analytics rule, you can select the relevant MITRE ATT&CK tactic and technique, which enriches the alert with threat intelligence context. Workbooks (Option D) are for visualization, not mapping. Playbooks (Option B) are for automated response. Watchlists (Option C) are for reference data. Therefore, Option A is correct.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Analytics rules
Why this is correct
Analytics rules in Microsoft Sentinel include a MITRE ATT&CK mapping section where each rule's tactics and techniques are configured. When the rule fires, generated incidents and alerts inherit those technique tags automatically, satisfying the requirement to categorise detected behaviours without manual enrichment.
- ✗
Playbooks
Why it's wrong here
Playbooks are Logic Apps workflows that run automated response actions after an alert fires; they execute remediation, they do not attach MITRE technique metadata to detections. They are tempting because they are triggered by alerts, but technique tagging happens in the analytics rule definition, before any playbook runs.
- ✗
Watchlists
Why it's wrong here
Watchlists are imported CSV tables used to correlate events against known entities such as IPs or VIP users; they store lookup data, not MITRE technique mappings. They are tempting because they enrich alerts, but the automatic ATT&CK tagging is configured on the analytics rule itself, not in a watchlist.
- ✗
Workbooks
Why it's wrong here
Workbooks render dashboards and visual reports from Log Analytics queries; they hold no mapping engine that tags alerts with MITRE technique IDs. They are tempting because hunting results are often visualised there, but the automatic technique mapping lives in the analytics rule's entity and alert configuration, not in a workbook.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.