Courseiva
Perform threat hunting →hardMultiple Select

SC-200 Perform threat hunting Practice Question

Which THREE of the following are key considerations when designing a threat hunting program in Microsoft Defender XDR and Microsoft Sentinel? (Choose THREE.)

⚠ Common exam trap

The trap is selecting general security controls like MFA as part of threat hunting design. Candidates must distinguish between foundational security hygiene and specific threat hunting program considerations.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Understanding the data schema and available tables in the advanced hunting schema

Option A is correct because effective threat hunting in Microsoft Defender XDR and Microsoft Sentinel requires knowing the advanced hunting schema — the exact table names (e.g., DeviceProcessEvents, DeviceNetworkEvents, EmailEvents, SigninLogs) and column/field types — so hunters can write precise KQL queries that surface relevant telemetry rather than guessing at data locations. Option B is correct because operational security (OpSec) matters during manual hunting: hunters must avoid actions that tip off adversaries, such as querying or interacting with compromised hosts in ways that generate detectable artifacts, since adversaries may monitor for reconnaissance and change their tactics, techniques, and procedures (TTPs) or go dormant. Option E is correct because data retention policies directly bound what a hunting program can investigate — Microsoft Sentinel's analytics and hunting queries can only search data within the configured retention period (interactive retention plus long-term retention tiers), and Defender XDR's advanced hunting is limited to its own retention window (typically 30 days), so retention must be planned to support historical hunting and incident reconstruction. Option C is not correct here because, while MFA is a critical identity security control, it is a general security hardening measure rather than a specific design consideration for a threat hunting program. Option D is not correct because relying only on built-in detection rules contradicts the purpose of threat hunting, which is proactive, hypothesis-driven investigation beyond automated detections; hunters use custom KQL queries, not just out-of-the-box rules.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Understanding the data schema and available tables in the advanced hunting schema

    Why this is correct

    A thorough understanding of the advanced hunting schema—including table names, column structure, and relationships—is essential for writing accurate and efficient KQL queries. Hunters must know, for example, that DeviceProcessEvents contains process creation data while IdentityLogonEvents holds authentication logs, and how to join these tables to trace lateral movement. Without this schema knowledge, analysts risk querying irrelevant tables, misinterpreting data, or missing critical evidence hidden in less obvious tables.

  • ✓

    Operational security (OpSec) to avoid tipping off adversaries during manual hunting

    Why this is correct

    Operational security (OpSec) is critical during manual hunting because adversary groups often monitor their own telemetry for signs of investigation. Actions such as running unusual KQL queries, accessing sensitive tables, or triggering specific detections can produce alerts or logs that a sophisticated attacker might notice, prompting them to adjust tactics, destroy evidence, or accelerate the attack. Therefore, hunters must understand what telemetry their own activities generate, use separate hunting accounts, and coordinate with incident response to avoid tipping off the adversary before containment.

  • ✗

    Implementing multi-factor authentication for all users

    Why it's wrong here

    Multi-factor authentication (MFA) is an essential security control for protecting user accounts, but it is not a hunting consideration. Threat hunting focuses on proactive search techniques, query development, and data analysis rather than access control mechanisms. While MFA reduces the risk of unauthorized access, it does not influence how you investigate logs, formulate hypotheses, or interpret adversary behavior—all of which are central to a hunt.

  • ✗

    Using only built-in detection rules to identify threats

    Why it's wrong here

    Using only built-in detection rules would limit hunting to known, signature-based patterns that already trigger alerts. Threat hunting is proactive and hypothesis-driven, requiring custom queries and exploratory analysis to uncover novel, subtle, or previously undetected threats that do not match existing rules. Built-in rules are valuable for automated detection, but they are only a starting point; hunters must extend beyond them to discover unknown adversary techniques and behavioral anomalies.

  • ✓

    Data retention policies for logs in Microsoft Sentinel and Microsoft Defender XDR

    Why this is correct

    Data retention policies directly determine the hunting time horizon because Microsoft Sentinel and Microsoft Defender XDR only allow queries against data that is still stored. If retention is too short, historical logs may be purged, making it impossible to investigate an initial compromise or detect gradual intrusions that occurred weeks ago. Therefore, hunters must understand retention limits, configure longer retention for critical data sources, and consider long-term archiving like Azure Data Lake to ensure sufficient historical visibility.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.