SC-200 Perform threat hunting Practice Question
During a threat hunt in Microsoft Defender XDR, you notice repeated failed logon attempts from an IP address that belongs to a known anonymizer service. What is the first action you should take?
⚠ Common exam trap
SC-200 often tests the order of incident response steps, and candidates may confuse containment with investigation, picking a blocking action before verifying the threat.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Initiate an investigation by reviewing the impacted user accounts and endpoints for signs of compromise.
In a threat hunt, the discovery of failed logons from an anonymizer IP is a potential indicator of compromise (IoC) that requires immediate validation. The first action should be to investigate the impacted user accounts and endpoints to determine if any logons succeeded or if there are other signs of malicious activity. This aligns with the incident response process of identification and scoping before taking containment or remediation actions. Blocking or creating rules without understanding the scope could disrupt legitimate activity or miss broader compromise.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Block the IP address in Microsoft Defender for Cloud Apps.
Why it's wrong here
Blocking a single anonymizer IP address in Microsoft Defender for Cloud Apps is a reactive containment action that lacks the context needed for a proper threat hunt. This type of IP is often dynamic or shared by many legitimate users across the internet, so prematurely blocking it can disrupt productivity without verifying whether an actual compromise occurred. The first priority should be to scope the incident by reviewing affected accounts and endpoints, leaving blocking as a targeted remediation step only after evidence supports it.
- ✗
Create an analytics rule in Microsoft Sentinel to alert on all anonymizer IP addresses.
Why it's wrong here
Creating a Microsoft Sentinel analytics rule that alerts on all anonymizer IP addresses is a broad, low-fidelity detection likely to generate a high volume of false positives, since VPNs, Tor exit nodes, and commercial proxies are commonly used for legitimate purposes. This approach does not address the current suspicious activity already noticed; it merely adds noise to the alert pipeline while shifting focus away from the immediate investigation. Threat hunting is hypothesis-driven and entity-centric, not based on blanket alerting for a single weak indicator like a public anonymizer IP.
- ✓
Initiate an investigation by reviewing the impacted user accounts and endpoints for signs of compromise.
Why this is correct
The correct initial action in a threat hunt is to pivot from the observed indicator—the anonymizer IP—to the associated entities, specifically the impacted user accounts and endpoints, and examine authentication logs, behavioral anomalies, and device telemetry for evidence of unauthorized access or lateral movement. Microsoft Defender XDR provides integrated signals such as IdentityLogonEvents, DeviceNetworkEvents, and alerts that enable this scoping, aligning with the MITRE ATT&CK technique of discovering the full attack surface. Only after determining whether accounts are compromised and what systems are affected can you make informed decisions on containment and remediation.
- ✗
Report the IP to the Microsoft Sentinel Threat Intelligence team.
Why it's wrong here
Reporting a single suspicious IP address to a 'Microsoft Sentinel Threat Intelligence team' is not a defined or established workflow in Microsoft Defender XDR; threat intelligence submissions typically occur after internal validation and for confirmed indicators of compromise, not as a reflexive first step. This action provides no investigative value for the current threat hunt and does not help determine whether the anonymizer IP is actually malicious in this specific context. The proper sequence is to conduct internal forensics on the impacted entities first, then optionally share verified indicators with threat intelligence platforms if they prove relevant.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.