Courseiva
Perform threat hunting →hardMultiple Select

SC-200 Perform threat hunting Practice Question

Which THREE of the following are recommended practices for creating effective threat hunting queries in Microsoft Sentinel? (Select three.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Include known indicators of compromise from threat feeds

Option C is correct because incorporating known indicators of compromise (IOCs) such as malicious IP addresses, domains, file hashes, and URLs from threat intelligence feeds lets hunting queries directly surface activity tied to known adversaries, which is a core recommended practice in Microsoft Sentinel. Option D is correct because mapping queries to MITRE ATT&CK techniques aligns hunting with specific adversary tactics and techniques, enabling coverage tracking, prioritization of gaps, and consistent query design across the kill chain. Option E is correct because constraining a query to a specific, relevant time range improves performance and reduces noise, ensuring the hunt focuses on the window of interest rather than scanning the entire retention period. Option A is not recommended because overly broad patterns generate excessive false positives and dilute the signal, and Option B is not recommended because excessive wildcard use degrades KQL query performance and precision, making results harder to triage.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use only broad patterns to avoid missing anything

    Why it's wrong here

    Broad patterns alone generate excessive noise and false positives, defeating the precision that effective hunting queries require. It is tempting because wide queries feel thorough and reduce the risk of overlooking activity, but hunting depends on targeted hypotheses, so broad-only patterns would be the choice when performing initial exploratory sweeps, not focused hunts.

  • ✗

    Use wildcards extensively to capture variations

    Why it's wrong here

    Extensive wildcards degrade query performance and inflate false positives, undermining the precision hunting queries need. It is tempting because wildcards do capture variations in indicators, which suits fuzzy matching, but recommended practise favours specific, tuned patterns; heavy wildcard use would fit broad exploratory searches rather than targeted hunts.

  • ✓

    Include known indicators of compromise from threat feeds

    Why this is correct

    Incorporating threat-feed indicators of compromise lets queries match observed malicious artefacts—IP addresses, domains, file hashes—against telemetry already ingested in Microsoft Sentinel, satisfying the stem's requirement for effective hunting queries. This converts external threat intelligence into concrete detection logic, surfacing known adversary infrastructure without waiting for an alert to fire.

  • ✓

    Map queries to MITRE ATT&CK techniques

    Why this is correct

    Mapping queries to MITRE ATT&CK techniques aligns hunts with adversary tactics, satisfying the recommended-practice requirement. It exposes coverage gaps and lets analysts pivot systematically across the kill chain instead of relying on ad hoc searches.

  • ✓

    Limit the query to a specific time range

    Why this is correct

    Restricting the query to a defined time range keeps hunting focused and performant, satisfying the stem's requirement for effective Microsoft Sentinel hunting queries. Unbounded searches across months of log data are slow, costly and noisy; scoping to the window of interest surfaces relevant anomalies faster and reduces false positives.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.