SC-200 Perform threat hunting Practice Question
Which THREE of the following are key considerations when designing a threat hunting program in Microsoft Defender XDR and Microsoft Sentinel? (Choose THREE.)
⚠ Common exam trap
The trap is selecting general security controls like MFA as part of threat hunting design. Candidates must distinguish between foundational security hygiene and specific threat hunting program considerations.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Understanding the data schema and available tables in the advanced hunting schema
Option A is correct because effective threat hunting in Microsoft Defender XDR and Microsoft Sentinel requires knowing the advanced hunting schema — the exact table names (e.g., DeviceProcessEvents, DeviceNetworkEvents, EmailEvents, SigninLogs) and column/field types — so hunters can write precise KQL queries that surface relevant telemetry rather than guessing at data locations. Option B is correct because operational security (OpSec) matters during manual hunting: hunters must avoid actions that tip off adversaries, such as querying or interacting with compromised hosts in ways that generate detectable artifacts, since adversaries may monitor for reconnaissance and change their tactics, techniques, and procedures (TTPs) or go dormant. Option E is correct because data retention policies directly bound what a hunting program can investigate — Microsoft Sentinel's analytics and hunting queries can only search data within the configured retention period (interactive retention plus long-term retention tiers), and Defender XDR's advanced hunting is limited to its own retention window (typically 30 days), so retention must be planned to support historical hunting and incident reconstruction. Option C is not correct here because, while MFA is a critical identity security control, it is a general security hardening measure rather than a specific design consideration for a threat hunting program. Option D is not correct because relying only on built-in detection rules contradicts the purpose of threat hunting, which is proactive, hypothesis-driven investigation beyond automated detections; hunters use custom KQL queries, not just out-of-the-box rules.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Understanding the data schema and available tables in the advanced hunting schema
Why this is correct
A thorough understanding of the advanced hunting schema—including table names, column structure, and relationships—is essential for writing accurate and efficient KQL queries. Hunters must know, for example, that DeviceProcessEvents contains process creation data while IdentityLogonEvents holds authentication logs, and how to join these tables to trace lateral movement. Without this schema knowledge, analysts risk querying irrelevant tables, misinterpreting data, or missing critical evidence hidden in less obvious tables.
- ✓
Operational security (OpSec) to avoid tipping off adversaries during manual hunting
Why this is correct
Operational security (OpSec) is critical during manual hunting because adversary groups often monitor their own telemetry for signs of investigation. Actions such as running unusual KQL queries, accessing sensitive tables, or triggering specific detections can produce alerts or logs that a sophisticated attacker might notice, prompting them to adjust tactics, destroy evidence, or accelerate the attack. Therefore, hunters must understand what telemetry their own activities generate, use separate hunting accounts, and coordinate with incident response to avoid tipping off the adversary before containment.
- ✗
Implementing multi-factor authentication for all users
Why it's wrong here
Multi-factor authentication (MFA) is an essential security control for protecting user accounts, but it is not a hunting consideration. Threat hunting focuses on proactive search techniques, query development, and data analysis rather than access control mechanisms. While MFA reduces the risk of unauthorized access, it does not influence how you investigate logs, formulate hypotheses, or interpret adversary behavior—all of which are central to a hunt.
- ✗
Using only built-in detection rules to identify threats
Why it's wrong here
Using only built-in detection rules would limit hunting to known, signature-based patterns that already trigger alerts. Threat hunting is proactive and hypothesis-driven, requiring custom queries and exploratory analysis to uncover novel, subtle, or previously undetected threats that do not match existing rules. Built-in rules are valuable for automated detection, but they are only a starting point; hunters must extend beyond them to discover unknown adversary techniques and behavioral anomalies.
- ✓
Data retention policies for logs in Microsoft Sentinel and Microsoft Defender XDR
Why this is correct
Data retention policies directly determine the hunting time horizon because Microsoft Sentinel and Microsoft Defender XDR only allow queries against data that is still stored. If retention is too short, historical logs may be purged, making it impossible to investigate an initial compromise or detect gradual intrusions that occurred weeks ago. Therefore, hunters must understand retention limits, configure longer retention for critical data sources, and consider long-term archiving like Azure Data Lake to ensure sufficient historical visibility.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.