SC-200 Perform threat hunting Practice Question
Which THREE of the following are recommended practices for creating effective threat hunting queries in Microsoft Sentinel? (Select three.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Include known indicators of compromise from threat feeds
Option C is correct because incorporating known indicators of compromise (IOCs) such as malicious IP addresses, domains, file hashes, and URLs from threat intelligence feeds lets hunting queries directly surface activity tied to known adversaries, which is a core recommended practice in Microsoft Sentinel. Option D is correct because mapping queries to MITRE ATT&CK techniques aligns hunting with specific adversary tactics and techniques, enabling coverage tracking, prioritization of gaps, and consistent query design across the kill chain. Option E is correct because constraining a query to a specific, relevant time range improves performance and reduces noise, ensuring the hunt focuses on the window of interest rather than scanning the entire retention period. Option A is not recommended because overly broad patterns generate excessive false positives and dilute the signal, and Option B is not recommended because excessive wildcard use degrades KQL query performance and precision, making results harder to triage.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use only broad patterns to avoid missing anything
Why it's wrong here
Broad patterns alone generate excessive noise and false positives, defeating the precision that effective hunting queries require. It is tempting because wide queries feel thorough and reduce the risk of overlooking activity, but hunting depends on targeted hypotheses, so broad-only patterns would be the choice when performing initial exploratory sweeps, not focused hunts.
- ✗
Use wildcards extensively to capture variations
Why it's wrong here
Extensive wildcards degrade query performance and inflate false positives, undermining the precision hunting queries need. It is tempting because wildcards do capture variations in indicators, which suits fuzzy matching, but recommended practise favours specific, tuned patterns; heavy wildcard use would fit broad exploratory searches rather than targeted hunts.
- ✓
Include known indicators of compromise from threat feeds
Why this is correct
Incorporating threat-feed indicators of compromise lets queries match observed malicious artefacts—IP addresses, domains, file hashes—against telemetry already ingested in Microsoft Sentinel, satisfying the stem's requirement for effective hunting queries. This converts external threat intelligence into concrete detection logic, surfacing known adversary infrastructure without waiting for an alert to fire.
- ✓
Map queries to MITRE ATT&CK techniques
Why this is correct
Mapping queries to MITRE ATT&CK techniques aligns hunts with adversary tactics, satisfying the recommended-practice requirement. It exposes coverage gaps and lets analysts pivot systematically across the kill chain instead of relying on ad hoc searches.
- ✓
Limit the query to a specific time range
Why this is correct
Restricting the query to a defined time range keeps hunting focused and performant, satisfying the stem's requirement for effective Microsoft Sentinel hunting queries. Unbounded searches across months of log data are slow, costly and noisy; scoping to the window of interest surfaces relevant anomalies faster and reduces false positives.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.