Courseiva
Perform threat hunting →hardMultiple Select

SC-200 Perform threat hunting Practice Question

Which THREE actions are recommended when conducting a threat hunting exercise in Microsoft Sentinel using the MITRE ATT&CK framework?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use the hunting queries from the Microsoft Sentinel Content hub as a starting point.

Options B, D, and E are recommended actions. B: Using hunting queries from the Microsoft Sentinel Content hub provides a validated starting point. D: Documenting findings and updating detection rules helps improve future hunts. E: Mapping hypotheses to MITRE ATT&CK tactics and techniques ensures comprehensive coverage. A is incorrect because focusing only on unseen techniques ignores known threats that may still be active. C is incorrect because relying exclusively on automated detection rules can miss advanced persistent threats that require manual hunting.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Focus only on techniques that have not been seen in your environment before.

    Why it's wrong here

    Focusing solely on unseen techniques ignores the ATT&CK coverage gap analysis that threat hunting depends on, where known techniques with no detection rule are the priority. It is tempting because novelty feels like the goal, and this approach suits exploratory research into emerging adversary tradecraft rather than validating existing Microsoft Sentinel analytics.

  • ✓

    Use the hunting queries from the Microsoft Sentinel Content hub as a starting point.

    Why this is correct

    Content hub hunting queries map to MITRE ATT&CK tactics and techniques, giving you pre-built KQL aligned to the framework's structure. This satisfies the scenario's requirement to conduct hunting within ATT&CK, letting you pivot from known technique coverage rather than authoring detections from scratch.

  • ✗

    Rely exclusively on automated detection rules to identify threats.

    Why it's wrong here

    Relying exclusively on automated detection rules contradicts threat hunting, which proactively queries logs for activity that rules have not flagged. Detection rules serve ongoing monitoring and alerting, and would be the right choice when the requirement is continuous, repeatable coverage of known techniques rather than hypothesis-driven investigation.

  • ✓

    Document your findings and update detection rules based on new patterns discovered.

    Why this is correct

    Documenting findings and updating detection rules closes the hunting loop, converting discovered adversary patterns into automated analytics rules within Microsoft Sentinel. This satisfies the exercise's requirement to operationalise insights, ensuring newly identified techniques are continuously detected rather than remaining one-off observations.

  • ✓

    Map your hunting hypotheses to specific MITRE ATT&CK tactics and techniques.

    Why this is correct

    Mapping hypotheses to specific MITRE ATT&CK tactics and techniques structures the hunt around adversary behaviour rather than raw telemetry, letting Microsoft Sentinel queries target the exact procedures expected. This satisfies the stem's requirement to conduct hunting within the framework, ensuring coverage is measurable against defined technique IDs instead of ad hoc searching.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.