Courseiva

SC-200 · topic practice

Perform threat hunting practice questions

This domain covers proactive threat hunting across Microsoft Sentinel, Defender XDR, and Defender for Cloud. You are tested on choosing the right data source or table, pivoting between entities like IPs, accounts, and devices, and recognizing KQL query limitations when correlating multi-stage attacker activity.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Perform threat hunting

What the exam tests

What to know about Perform threat hunting

Be able to pick the correct Microsoft Sentinel or Defender XDR data source, pivot across entities like IPs, accounts, and devices, and spot KQL query limitations. The most important skill is mapping a hunt question to the exact table and entity that answers it.

Selecting Defender for Endpoint tables such as DeviceNetworkEvents for process-to-IP connection hunting

Pivoting on entities in Microsoft Sentinel, including IP addresses and Microsoft Entra ID sign-in accounts

Correlating alerts across Azure subscriptions using Defender for Cloud and Microsoft Sentinel workbooks

Recognizing limitations of KQL queries, such as time ranges, joins, and result caps

Watch out for

Common Perform threat hunting exam traps

  • ▸Using DeviceProcessEvents instead of DeviceNetworkEvents when the hunt requires remote IP and port connection data
  • ▸Failing to pivot from a suspicious sign-in IP to related accounts, devices, and subsequent activity in Sentinel
  • ▸Assuming a KQL query covers all data when it lacks a time filter, join, or sufficient result limit

Practice set

Perform threat hunting questions

20 questions · select your answer, then reveal the explanation

During a threat hunt in Microsoft Sentinel, an analyst creates a custom hunting query that uses the 'externaldata' operator to reference a CSV file stored in Azure Blob Storage. The hunt identifies several suspicious IP addresses that need to be added to a threat intelligence indicator. Which method should the analyst use to persist the findings as indicators of compromise (IOCs) for automated alerting?

A threat hunter is using Microsoft Sentinel to hunt for signs of privilege escalation via Azure AD role assignment changes. Which TWO KQL operators or functions are most useful for identifying changes that added a user to a high-privilege role?

Question 3hardmulti select
Read the full DNS explanation →

A threat hunter is investigating a potential data exfiltration via DNS tunneling using Microsoft Defender for Endpoint advanced hunting. Which THREE columns from the DeviceNetworkEvents table should the hunter include in a query to detect anomalous DNS queries?

A security analyst is using Microsoft Sentinel to hunt for signs of a brute-force attack against Azure AD. Which TWO data sources are most relevant for this hunt?

A threat hunter runs the KQL query above in Microsoft Sentinel to detect accounts that have experienced multiple failed sign-in attempts due to a disabled account (ResultType 50057) from the same IP. The query returns no results even though the hunter knows that some disabled accounts are being attacked. What is the most likely reason for the false negatives?

Exhibit

Refer to the exhibit.

```kql
let threshold = 5;
SigninLogs
| where TimeGenerated > ago(1h)
| where ResultType == "50057"  // User account is disabled
| summarize FailedAttempts = count() by UserPrincipalName, IPAddress
| where FailedAttempts > threshold
| project UserPrincipalName, IPAddress, FailedAttempts
```

A threat hunter writes the KQL query above in Microsoft Defender for Endpoint advanced hunting to find devices where a script host process was launched with encoded commands and then connected to an HTTPS endpoint within 10 minutes. The query is syntactically correct but returns no results. The hunter knows that such activity has occurred. What is the most likely reason?

Exhibit

Refer to the exhibit.

```kql
DeviceProcessEvents
| where Timestamp > ago(7d)
| where FileName in~ ("powershell.exe", "cmd.exe", "wscript.exe", "cscript.exe")
| where ProcessCommandLine contains "-enc" or ProcessCommandLine contains "-e "
| project Timestamp, DeviceName, AccountName, FileName, ProcessCommandLine
| join kind=inner (
    DeviceNetworkEvents
    | where Timestamp > ago(7d)
    | where RemotePort == 443
    | project Timestamp, DeviceName, RemoteUrl
) on DeviceName, Timestamp
| where Timestamp between (Timestamp1 .. Timestamp1 + 10m)
```

A threat hunter in Microsoft Sentinel is reviewing a JSON definition for a scheduled analytics rule as shown in the exhibit. The rule is intended to run daily and alert on any device running powershell.exe with an encoded command. However, no alerts have been generated even though the hunter knows such activity exists. What is the most likely cause?

Exhibit

Refer to the exhibit.

```json
{
  "properties": {
    "displayName": "Hunt for suspicious PowerShell",
    "description": "Detects PowerShell with encoded commands",
    "tactics": ["Execution"],
    "techniques": ["T1059.001"],
    "requiredDataConnectors": [
      { "connectorId": "MicrosoftThreatProtection", "dataTypes": ["DeviceProcessEvents"] }
    ],
    "queryPeriod": "14d",
    "queryFrequency": "1d",
    "triggerOperator": "gt",
    "triggerThreshold": 0,
    "query": "DeviceProcessEvents | where FileName == 'powershell.exe' and ProcessCommandLine contains '-enc'",
    "suppressionEnabled": false
  }
}
```

Your threat hunt aims to detect possible Kerberoasting attacks. Which KQL query in Microsoft Sentinel would best identify service principal name (SPN) requests from unusual accounts?

During a hunt, you find that a user account has logged in from an IP address associated with a known command-and-control (C2) server. The hunt also reveals that the same IP accessed a SharePoint site containing sensitive documents. Which Microsoft Purview feature should you use to investigate data exfiltration?

Your threat hunt identifies that an attacker used a previously unknown malware variant to move laterally. Which Microsoft Defender XDR feature would you use to automatically block the file based on behavioral detection?

You are investigating a potential DCSync attack. Which Advanced Hunting query in Microsoft Defender XDR would best detect a process making atypical directory replication requests?

You are hunting for signs of pass-the-hash (PtH) attacks. Which Windows Security Event ID should you focus on to detect anomalous NTLM authentication using a hash?

A security analyst is using Microsoft Sentinel to hunt for signs of Kerberos golden ticket attacks. Which KQL function is most appropriate to identify anomalous Kerberos service ticket requests?

During a hunt, you find a device that made successive outbound connections to multiple IP addresses on port 445 (SMB) within a short time. Which type of activity does this pattern most likely indicate?

You are hunting for signs of Pass-the-Hash attacks using Microsoft Defender for Identity. Which alert should you look for in Microsoft Defender XDR?

Question 16hardmultiple choice
Read the full DNS explanation →

A threat hunter suspects a data exfiltration attempt via DNS tunneling. Which KQL query would best detect unusual DNS query patterns in Microsoft Sentinel?

Which TWO Microsoft Sentinel hunting features can be used to automatically surface suspicious activities without manual query writing?

You are reviewing a hunting query that identifies accounts with failed logons followed by successful logons from the same IP. The query returns no results even though you suspect brute force activity. What is the most likely issue?

Exhibit

Refer to the exhibit.
```kusto
// KQL query used in a Sentinel hunting query
let TimeWindow = 1h;
let Threshold = 5;
let FailedLogons = 
    SecurityEvent
    | where TimeGenerated > ago(TimeWindow)
    | where EventID == 4625
    | summarize FailedCount = count() by Account, SourceIP
    | where FailedCount > Threshold;
FailedLogons
| join kind=inner (
    SecurityEvent
    | where TimeGenerated > ago(TimeWindow)
    | where EventID == 4624
    | summarize LogonCount = count() by Account, SourceIP
) on Account, SourceIP
| where LogonCount > 0
```

You are creating a custom hunting query in Microsoft Sentinel for PowerShell Empire indicators. After deploying, the query never returns results, even though you know empire activity exists in the environment. What is the most likely cause?

Exhibit

Refer to the exhibit.
```json
{
  "properties": {
    "displayName": "Hunt for PowerShell Empire",
    "description": "Searches for common PowerShell Empire indicators",
    "query": "DeviceProcessEvents | where FileName == 'powershell.exe' and ProcessCommandLine contains 'Reflection.Assembly' or ProcessCommandLine contains 'System.Net.WebClient'",
    "tactics": ["Execution"],
    "techniques": ["T1059.001"],
    "inputEntityType": "host",
    "requiredDataConnectors": [
      {
        "connectorId": "MicrosoftThreatProtection"
      }
    ]
  }
}

A threat hunter runs this KQL query to find devices making many outbound SMB connections. The result shows a device 'DC01' connecting to over 100 different IPs on port 445. What is the most likely explanation?

Exhibit

Refer to the exhibit.
```kusto
// KQL query in Microsoft Sentinel hunting
DeviceNetworkEvents
| where Timestamp > ago(7d)
| where RemotePort == 445
| summarize TotalConnections = count() by DeviceName, RemoteIP
| where TotalConnections > 100
| project DeviceName, RemoteIP, TotalConnections
```

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Perform threat hunting sessions

Start a Perform threat hunting only practice session

Every question in these sessions is drawn from the Perform threat hunting domain — nothing else.

Related practice questions

Related SC-200 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the SC-200 exam test about Perform threat hunting?
Be able to pick the correct Microsoft Sentinel or Defender XDR data source, pivot across entities like IPs, accounts, and devices, and spot KQL query limitations. The most important skill is mapping a hunt question to the exact table and entity that answers it.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Perform threat hunting questions in a focused session?
Yes — the session launcher on this page draws every question from the Perform threat hunting domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other SC-200 topics?
Use the topic links above to move to related areas, or go back to the SC-200 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the SC-200 exam covers. They are not copied from any real exam or dump site.