Courseiva
mediumDrag & Drop

SC-200 Practice Question: Order the steps to perform a threat hunting…

Order the steps to perform a threat hunting exercise using Microsoft 365 Defender advanced hunting.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Step 1: Hypothesis, Step 2: Query, Step 3: Analyze, Step 4: Document

Threat hunting starts with a hypothesis, then querying, analyzing, and documenting results.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Step 1: Hypothesis, Step 2: Query, Step 3: Analyze, Step 4: Document

    Why this is correct

    This is the correct order because threat hunting begins with a hypothesis to guide the search, then uses advanced hunting queries to gather data, analyzes the results to identify threats, and finally documents findings for remediation.

  • ✗

    Step 1: Query, Step 2: Hypothesis, Step 3: Analyze, Step 4: Document

    Why it's wrong here

    This order is incorrect because a threat hunt should never begin with a raw advanced hunting query; without an explicit security hypothesis (e.g., a compromised account abusing scheduled tasks for persistence), the query lacks direction and often returns a high volume of unrelated events. The hypothesis is what defines the specific entities, time range, and behavior patterns to search for, so skipping it until after the query leads to inefficient, scattershot analysis.

  • ✗

    Step 1: Hypothesis, Step 2: Analyze, Step 3: Query, Step 4: Document

    Why it's wrong here

    Placing analysis before the query is logically impossible because analysis is the interpretation of data that has already been collected by the query. In Microsoft 365 Defender advanced hunting, a KQL query is the execution vehicle that pulls the relevant raw telemetry (e.g., IdentityLogonEvents, ProcessEvents) into a dataset; only after that dataset is returned can the hunter triage, correlate, and assess it for malicious activity.

  • ✗

    Step 1: Query, Step 2: Analyze, Step 3: Hypothesis, Step 4: Document

    Why it's wrong here

    Delaying the hypothesis until after both query and analysis turns the exercise into reactive data-mining rather than proactive threat hunting. The entire point of a hypothesis is to shape the query's filters and guide the analysis; if you only form a hypothesis after you've already analyzed the results, you are not testing a theory, and you may force a conclusion onto unrelated findings, weakening the evidential value of the hunt.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.