Courseiva
Perform threat hunting →mediumMultiple Choice

SC-200 Perform threat hunting Practice Question

During a threat hunt, you find an alert for a suspicious PowerShell script that encoded a payload. You want to decode the script to understand its intent. Which Microsoft Sentinel feature can assist with this task?

⚠ Common exam trap

The trap is confusing Sentinel features: candidates might think Playbooks or Analytics rules can decode data, but only the Hunting blade with KQL provides that capability.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Hunting blade with KQL using base64_decode_tostring()

Microsoft Sentinel's Hunting blade allows security analysts to run KQL queries across logged data. The function base64_decode_tostring() can decode Base64-encoded strings, such as those found in obfuscated PowerShell scripts. This enables threat hunters to reveal the script's intent. Playbooks are for automation, Workbooks for visualization, and Analytics rules for alert generation, none of which directly decode payloads.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Playbooks

    Why it's wrong here

    In Microsoft Sentinel, playbooks are automated workflows built on Azure Logic Apps that execute response actions, such as isolating a machine or notifying an admin, when triggered by an analytics rule or incident. They do not provide a mechanism to inspect or decode the raw content of a suspicious PowerShell command. To decode Base64-encoded command lines, the analyst must query the underlying Log Analytics workspace, e.g., via the Hunting blade with KQL's base64_decode_tostring(), not trigger a playbook. Therefore, using a playbook would not accomplish the decoding task.

  • ✗

    Workbooks

    Why it's wrong here

    Sentinel workbooks are interactive dashboards that visualize data from queries, often used for reporting and monitoring trends, but they are not query editors for ad-hoc investigation. While a workbook can include KQL queries, its purpose is presentation, not deep-diving into a single suspicious alert to decode command-line payloads. The Hunting blade is the dedicated interface for iterative, hypothesis-driven threat hunting and provides direct access to KQL string functions like base64_decode_tostring(). Thus, workbooks are the wrong tool for decoding a specific suspicious PowerShell command.

  • ✓

    Hunting blade with KQL using base64_decode_tostring()

    Why this is correct

    The Hunting blade in Microsoft Sentinel provides a KQL query environment tailored for proactive threat hunting. KQL includes built-in string functions, and base64_decode_tostring() specifically converts a Base64-encoded input to its plain-text string representation, which is ideal for decoding obfuscated PowerShell commands that attackers often encode using Base64. Running a KQL query against the relevant table (e.g., DeviceProcessEvents) with this function reveals the actual command executed, enabling further analysis. This is the correct approach because it directly transforms the encoded data into readable content.

  • ✗

    Analytics rules

    Why it's wrong here

    Analytics rules in Microsoft Sentinel are used to create alerts by continuously running scheduled queries that look for suspicious activity, and they do not provide a function to decode content after the fact. While an analyst could theoretically write a query with base64_decode_tostring() inside an analytics rule, the rule's purpose is detection and alert generation, not interactive investigation of a single alert. Additionally, rules operate on a schedule and are not designed for on-demand hunting or manual decoding of a specific event. The Hunting blade is the appropriate tool for this ad-hoc, post-detection analysis.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.