Courseiva
Perform threat hunting →hardMultiple Select

SC-200 Perform threat hunting Practice Question

Which THREE are essential components of a threat hunting hypothesis in Microsoft Sentinel? (Choose three.)

⚠ Common exam trap

SC-200 often tests whether candidates can separate the hunting hypothesis (goal, data, expected evidence) from detection and response artifacts (severity, playbooks) — the distractor options sound relevant to security operations but are not part of the hypothesis construct.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Adversary goal or objective

A threat hunting hypothesis in Microsoft Sentinel must be structured around what the adversary is trying to achieve, so option A (Adversary goal or objective) is correct because it defines the behavior or intent being tested, such as credential theft or lateral movement, which guides the entire hunt. Option C (Data sources to query) is correct because a hypothesis is only actionable if it maps to concrete telemetry in Sentinel, such as SecurityEvent, Syslog, SigninLogs, or OfficeActivity tables queried via KQL, so the hunter knows where to look. Option E (Expected indicators of compromise (IOCs)) is correct because the hypothesis must specify the observable artifacts that would confirm or refute it, such as specific process names, IP addresses, hashes, or anomalous sign-in patterns, enabling validation of the hunt. Option B (Alert severity level) is not essential because severity is a triage attribute of analytics rules and incidents, not a defining element of a hunting hypothesis. Option D (Automated response plan) is not essential because automation and playbooks belong to incident response and SOAR workflows, whereas threat hunting is an investigative, hypothesis-driven activity that may not trigger automated actions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Adversary goal or objective

    Why this is correct

    A hypothesis must state what the adversary is trying to achieve, since the goal directs which behaviours, telemetry and queries the hunter pursues. Without an objective, hunting lacks a testable premise and becomes unfocused data review.

  • ✗

    Alert severity level

    Why it's wrong here

    Alert severity is a triage attribute of generated incidents, not part of a hunting hypothesis, which states the actor, behaviour, and data sources to query. It tempts because severity guides prioritisation, but it would be correct when ranking alerts, not framing proactive hunts.

  • ✓

    Data sources to query

    Why this is correct

    Naming the data sources to query makes the hypothesis testable, because the hunter must know which telemetry can evidence the suspected behaviour. It links the adversary objective to concrete Microsoft Sentinel tables and log sets.

  • ✗

    Automated response plan

    Why it's wrong here

    A hypothesis states what behaviour you expect to observe and the data that would confirm it; an automated response plan is a post-detection action, not part of the hypothesis itself. It is tempting because response automation is central to Sentinel playbooks, and it would be the right answer to a question about incident remediation workflows.

  • ✓

    Expected indicators of compromise (IOCs)

    Why this is correct

    A hypothesis must state what evidence would confirm or refute it. Expected IOCs define the observable artefacts, such as hashes or domains, that Microsoft Sentinel queries surface, letting hunters validate the hypothesis against telemetry rather than speculate.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.