Courseiva
Perform threat hunting →hardMultiple Select

SC-200 Perform threat hunting Practice Question

Which THREE of the following are best practices for performing threat hunting in Microsoft Defender XDR? (Select THREE.)

⚠ Common exam trap

SC-200 often tests the misconception that threat hunting equals reviewing automated alerts, when the exam expects candidates to recognize hunting as a proactive, hypothesis-driven, cross-domain activity.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Start with a hypothesis based on threat intelligence or recent incidents.

Option C is correct because effective threat hunting in Microsoft Defender XDR is hypothesis-driven: analysts should begin with a testable hypothesis derived from threat intelligence, known adversary TTPs, or lessons learned from recent incidents, then validate or refute it with data. Option D is correct because advanced hunting in Defender XDR relies on KQL (Kusto Query Language) queries against the unified schema, and combining custom KQL with built-in hunting capabilities (such as built-in queries, hunting graphs, and detection-rule creation from query results) gives both flexibility and efficiency. Option E is correct because Defender XDR's core strength is cross-domain correlation, so hunting should span the unified advanced hunting tables covering devices (DeviceEvents, DeviceProcessEvents), email (EmailEvents, EmailAttachmentInfo), and identities (IdentityLogonEvents, IdentityInfo) to surface multi-stage attacks that a single workload would miss. Option A is not a best practice because relying only on automated detection alerts is reactive alert triage, not proactive hunting for threats that evade existing detections. Option B is not a best practice because restricting hunting to a single data source defeats the purpose of Defender XDR's unified, cross-domain telemetry and hides correlated attack chains.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Focus only on alerts generated by automated detection rules.

    Why it's wrong here

    Focusing only on automated alerts contradicts threat hunting, which proactively queries raw telemetry in advanced hunting to surface activity that detection rules missed. Automated alerts suit triage and incident response, where analysts work known detections. In a hunting scenario, that approach simply re-examines what Defender XDR already flagged, leaving undetected threats undiscovered.

  • ✗

    Limit hunting to a single data source to reduce complexity.

    Why it's wrong here

    Restricting hunting to one data source prevents correlating signals across endpoints, identity and email, which is how Microsoft Defender XDR surfaces multi-stage attacks. It is tempting because narrowing scope does reduce query complexity, and single-source hunting suits targeted investigations within one workload, such as Defender for Endpoint alone.

  • ✓

    Start with a hypothesis based on threat intelligence or recent incidents.

    Why this is correct

    A hypothesis grounded in threat intelligence or recent incidents directs hunting toward plausible adversary behaviour rather than unfocused querying. This satisfies the stem's best-practise criterion by making hunting purposeful and evidence-driven within Microsoft Defender XDR.

  • ✓

    Use a combination of KQL queries and built-in hunting capabilities.

    Why this is correct

    Combining custom KQL queries with built-in hunting capabilities covers both bespoke hypotheses and Microsoft's curated detections, giving broader coverage than either alone. This directly satisfies the stem's requirement for effective threat-hunting practise in Microsoft Defender XDR.

  • ✓

    Leverage advanced hunting across devices, email, and identities.

    Why this is correct

    Advanced hunting in Microsoft Defender XDR unifies device, email and identity telemetry into one schema, so a single query correlates signals across all three workloads. This cross-domain visibility is what the stem's best-practise requirement demands.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.