Drag or tap steps into the slots.
SC-200 Practice Question: Order the steps to perform a threat hunting…
Order the steps to perform a threat hunting exercise using Microsoft 365 Defender advanced hunting.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
Step 1: Hypothesis, Step 2: Query, Step 3: Analyze, Step 4: Document
Threat hunting starts with a hypothesis, then querying, analyzing, and documenting results.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Step 1: Hypothesis, Step 2: Query, Step 3: Analyze, Step 4: Document
Why this is correct
This is the correct order because threat hunting begins with a hypothesis to guide the search, then uses advanced hunting queries to gather data, analyzes the results to identify threats, and finally documents findings for remediation.
- ✗
Step 1: Query, Step 2: Hypothesis, Step 3: Analyze, Step 4: Document
Why it's wrong here
This order is incorrect because a threat hunt should never begin with a raw advanced hunting query; without an explicit security hypothesis (e.g., a compromised account abusing scheduled tasks for persistence), the query lacks direction and often returns a high volume of unrelated events. The hypothesis is what defines the specific entities, time range, and behavior patterns to search for, so skipping it until after the query leads to inefficient, scattershot analysis.
- ✗
Step 1: Hypothesis, Step 2: Analyze, Step 3: Query, Step 4: Document
Why it's wrong here
Placing analysis before the query is logically impossible because analysis is the interpretation of data that has already been collected by the query. In Microsoft 365 Defender advanced hunting, a KQL query is the execution vehicle that pulls the relevant raw telemetry (e.g., IdentityLogonEvents, ProcessEvents) into a dataset; only after that dataset is returned can the hunter triage, correlate, and assess it for malicious activity.
- ✗
Step 1: Query, Step 2: Analyze, Step 3: Hypothesis, Step 4: Document
Why it's wrong here
Delaying the hypothesis until after both query and analysis turns the exercise into reactive data-mining rather than proactive threat hunting. The entire point of a hypothesis is to shape the query's filters and guide the analysis; if you only form a hypothesis after you've already analyzed the results, you are not testing a theory, and you may force a conclusion onto unrelated findings, weakening the evidential value of the hunt.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.