SC-200 Perform threat hunting Practice Question
Which THREE Microsoft Sentinel features are specifically designed to assist with threat hunting?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Livestream for real-time hunting.
Option A, Livestream for real-time hunting, is correct because Microsoft Sentinel's Livestream feature lets analysts run a hunting query continuously and view results as they occur, which is specifically built for interactive, real-time threat hunting rather than post-incident reporting. Option C, Bookmarks to record interesting results, is correct because bookmarks preserve notable entities, events, or query results from hunting activities so they can be retained, tagged, and later promoted into incidents or used in investigations. Option E, The Hunting blade with built-in and custom queries, is correct because the Hunting blade in Microsoft Sentinel provides prebuilt KQL hunting queries mapped to MITRE ATT&CK techniques plus the ability to create and run custom queries, making it the core hunting workspace. Option B, Workbooks for interactive dashboards, is not marked correct because workbooks are primarily used for visualization, monitoring, and reporting on data rather than being a dedicated hunting tool. Option D, Automation rules to respond to incidents, is not marked correct because automation rules orchestrate incident handling, triage, and response actions, which is an SOAR capability rather than a threat-hunting feature.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Livestream for real-time hunting.
Why this is correct
Livestream streams events in real time as they are ingested, letting hunters watch activity unfold without waiting for scheduled analytics rules to fire. This satisfies the scenario's requirement for a hunting feature, since interactive, near-instant event visibility directly supports proactive investigation rather than automated detection alone.
- ✗
Workbooks for interactive dashboards.
Why it's wrong here
Workbooks render visual dashboards over saved queries for monitoring and reporting, not for iteratively exploring raw log data. It is tempting because dashboards genuinely surface security data, but hunting instead relies on hunting queries, bookmarks and livestream, which let analysts search logs and preserve findings during an investigation.
- ✓
Bookmarks to record interesting results.
Why this is correct
Bookmarks preserve specific rows and entities returned by a hunting query, along with notes, so investigators can record interesting findings and pivot back to them later. This satisfies the requirement to capture and revisit hunting results.
- ✗
Automation rules to respond to incidents.
Why it's wrong here
Automation rules trigger playbooks or incident actions after an alert fires, which is response rather than proactive hunting. It is tempting because automation genuinely supports security operations, but hunting features instead include hunting queries, bookmarks and livestream, which let analysts search raw logs and preserve findings before any incident exists.
- ✓
The Hunting blade with built-in and custom queries.
Why this is correct
The Hunting blade provides built-in and custom queries that hunters run across ingested data to proactively search for threats, forming the core hunting workspace in Microsoft Sentinel. It directly satisfies the requirement for query-driven threat hunting.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SC-200
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which TWO of the following are valid approaches to perform threat hunting using Microsoft Sentinel? (Choose two.)
hard- A.Using Fusion analytics rule
- ✓ B.Using the Hunting blade and Livestream
- C.Using Automation rules to trigger playbooks
- ✓ D.Using KQL queries in the Logs blade
- E.Using Azure Policy to enforce compliance
Why B: The Hunting blade in Microsoft Sentinel provides a dedicated interface for proactive threat hunting, allowing analysts to run KQL queries and pivot through results. Livestream extends this by enabling continuous, real-time query execution against incoming data, which is essential for detecting patterns that evolve over minutes or hours. Both features are explicitly designed for iterative, hypothesis-driven threat hunting rather than automated detection.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.