Courseiva
Perform threat hunting →mediumMultiple Select

SC-200 Perform threat hunting Practice Question

Which THREE of the following are valid sources of threat intelligence that can be ingested into Microsoft Sentinel for threat hunting? (Select three.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Threat Intelligence feed

Microsoft Sentinel natively ingests threat intelligence through the Microsoft Defender Threat Intelligence (MDTI) connector, so option B (Microsoft Threat Intelligence feed) is a valid source that populates the ThreatIntelligenceIndicator table for hunting. Option C (TAXII server) is correct because Sentinel supports the Threat Intelligence - TAXII data connector, which pulls STIX/TAXII 2.x indicators from a TAXII 2.0/2.1 endpoint. Option D (Custom threat intelligence via API) is correct because Sentinel exposes the Upload Indicators API (Microsoft Sentinel Threat Intelligence Upload API) and the Graph Security tiIndicators API, allowing custom or third-party feeds to be pushed programmatically. Option A (Syslog from a firewall) is not a threat intelligence source; it is raw log telemetry ingested via the Syslog/CEF connector for detection, not curated indicator data. Option E (Azure Policy) is a governance/compliance service for enforcing resource configurations and has no role in ingesting threat intelligence indicators.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Syslog from a firewall

    Why it's wrong here

    Raw syslog from a firewall is unprocessed log data, not a threat intelligence feed; Sentinel ingests it as a log source for analytics rules, not as indicator-of-compromise enrichment. Syslog suits custom detection queries, whereas threat intelligence requires structured STIX or TAXII indicator feeds.

  • ✓

    Microsoft Threat Intelligence feed

    Why this is correct

    Microsoft Threat Intelligence feed is natively integrated with Microsoft Sentinel, providing curated indicators of compromise from Microsoft's global telemetry. It satisfies the stem's ingestion requirement without custom connectors, unlike external feeds needing API configuration. This built-in source enriches threat hunting queries directly.

  • ✓

    TAXII server

    Why this is correct

    TAXII servers publish structured STIX threat indicators over a RESTful API, and Microsoft Sentinel's data connectors can poll a TAXII 2.0/2.1 endpoint to ingest those indicators continuously. This satisfies the stem's requirement for a valid ingested threat intelligence source, feeding watchlists and analytics rules for hunting.

  • ✓

    Custom threat intelligence via API

    Why this is correct

    Microsoft Sentinel exposes a threat intelligence upload API, letting analysts push custom STIX indicators programmatically. This satisfies the stem's requirement for a valid ingestion source, covering bespoke or internal indicators that commercial feeds do not supply.

  • ✗

    Azure Policy

    Why it's wrong here

    Azure Policy enforces governance rules and audits resource compliance; it produces no indicators of compromise or adversary data for Sentinel's threat intelligence connectors. It is tempting because it feeds Sentinel, but as configuration-compliance telemetry rather than intel. It would be correct when enforcing organisational standards across Azure subscriptions.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.