SC-200 Perform threat hunting Practice Question
Which THREE actions are recommended when conducting a threat hunting exercise in Microsoft Sentinel using the MITRE ATT&CK framework?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use the hunting queries from the Microsoft Sentinel Content hub as a starting point.
Options B, D, and E are recommended actions. B: Using hunting queries from the Microsoft Sentinel Content hub provides a validated starting point. D: Documenting findings and updating detection rules helps improve future hunts. E: Mapping hypotheses to MITRE ATT&CK tactics and techniques ensures comprehensive coverage. A is incorrect because focusing only on unseen techniques ignores known threats that may still be active. C is incorrect because relying exclusively on automated detection rules can miss advanced persistent threats that require manual hunting.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Focus only on techniques that have not been seen in your environment before.
Why it's wrong here
Focusing solely on unseen techniques ignores the ATT&CK coverage gap analysis that threat hunting depends on, where known techniques with no detection rule are the priority. It is tempting because novelty feels like the goal, and this approach suits exploratory research into emerging adversary tradecraft rather than validating existing Microsoft Sentinel analytics.
- ✓
Use the hunting queries from the Microsoft Sentinel Content hub as a starting point.
Why this is correct
Content hub hunting queries map to MITRE ATT&CK tactics and techniques, giving you pre-built KQL aligned to the framework's structure. This satisfies the scenario's requirement to conduct hunting within ATT&CK, letting you pivot from known technique coverage rather than authoring detections from scratch.
- ✗
Rely exclusively on automated detection rules to identify threats.
Why it's wrong here
Relying exclusively on automated detection rules contradicts threat hunting, which proactively queries logs for activity that rules have not flagged. Detection rules serve ongoing monitoring and alerting, and would be the right choice when the requirement is continuous, repeatable coverage of known techniques rather than hypothesis-driven investigation.
- ✓
Document your findings and update detection rules based on new patterns discovered.
Why this is correct
Documenting findings and updating detection rules closes the hunting loop, converting discovered adversary patterns into automated analytics rules within Microsoft Sentinel. This satisfies the exercise's requirement to operationalise insights, ensuring newly identified techniques are continuously detected rather than remaining one-off observations.
- ✓
Map your hunting hypotheses to specific MITRE ATT&CK tactics and techniques.
Why this is correct
Mapping hypotheses to specific MITRE ATT&CK tactics and techniques structures the hunt around adversary behaviour rather than raw telemetry, letting Microsoft Sentinel queries target the exact procedures expected. This satisfies the stem's requirement to conduct hunting within the framework, ensuring coverage is measurable against defined technique IDs instead of ad hoc searching.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.