Courseiva
Perform threat huntinghardMultiple SelectObjective-mapped

SC-200 Perform threat hunting Practice Question

Which THREE actions are part of the threat hunting process in Microsoft Defender XDR?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Investigate entities found in the results

Formulating a hypothesis, querying advanced hunting, and investigating entities are core steps. Configuring automated responses is part of incident response, and setting retention policies is data management.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Configure automated response actions

    Why it's wrong here

    Configuring automated response actions, such as AIR playbooks, device isolation, or email purge in Microsoft Defender XDR, is an incident-response and remediation activity that occurs after a threat has been confirmed, not a step in the proactive threat hunting cycle. Threat hunting is an iterative, hypothesis-driven process focused on manually discovering and validating malicious activity through data exploration; automating response actions is a downstream outcome once a hunting finding has been escalated. Including it in the hunting process would conflate detection with remediation.

  • Investigate entities found in the results

    Why this is correct

    Investigating entities found in the query results is a defining threat-hunting action because it requires pivoting from raw data to the entity pages for users, devices, files, IPs, or mailboxes, then reviewing timelines, related alerts, and correlated events to decide whether the behavior is genuinely malicious. This validation step is what confirms or refutes the original hypothesis and reveals the scope of the threat. Without entity-level investigation, a hunter cannot distinguish a true positive from a benign anomaly or a false positive.

  • Query advanced hunting using KQL

    Why this is correct

    Querying advanced hunting using KQL is the primary execution step in Microsoft Defender XDR, where the hunter writes structured Kusto queries across telemetry tables such as DeviceProcessEvents, IdentityLogonEvents, EmailEvents, and AlertEvidence. This step allows the hunter to test the hypothesis by seeking specific behavioral patterns, such as unusual parent-child process chains, impossible-travel sign-ins, or suspicious file downloads. Iteratively refining and rerunning these queries is what makes Advanced Hunting the core engine for proactive threat validation.

  • Formulate a hypothesis based on threat intelligence

    Why this is correct

    Formulating a hypothesis based on threat intelligence is the foundational first step of threat hunting; for example, an intelligence report about a new adversary technique could lead the hunter to hypothesize that a particular PowerShell obfuscation pattern or rare remote-management tool might already be present in the environment. This hypothesis gives the hunt a measurable direction by defining which data sources, time windows, and behavioral indicators need to be examined. It ensures that every subsequent query and entity investigation is purposeful and threat-informed rather than random exploration.

  • Set data retention policies for hunting data

    Why it's wrong here

    Setting data retention policies, such as configuring Microsoft 365 retention settings, Log Analytics workspace retention, or Defender XDR data storage duration, is a data-governance and compliance activity that determines how long telemetry remains available for historical search; it is not an analytic action performed during an active hunt. While having sufficient retention is a prerequisite for long-term hunting, changing retention policies is a separate administrative task and does not belong to the series of actions a hunter performs while hunting. Therefore, it is not one of the three key actions in the threat hunting process.

About these practice questions

This SC-200 question is part of Courseiva's 673-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.