SC-200 Perform threat hunting Practice Question
Which THREE of the following are valid sources of threat intelligence that can be ingested into Microsoft Sentinel for threat hunting? (Select three.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Threat Intelligence feed
Microsoft Sentinel natively ingests threat intelligence through the Microsoft Defender Threat Intelligence (MDTI) connector, so option B (Microsoft Threat Intelligence feed) is a valid source that populates the ThreatIntelligenceIndicator table for hunting. Option C (TAXII server) is correct because Sentinel supports the Threat Intelligence - TAXII data connector, which pulls STIX/TAXII 2.x indicators from a TAXII 2.0/2.1 endpoint. Option D (Custom threat intelligence via API) is correct because Sentinel exposes the Upload Indicators API (Microsoft Sentinel Threat Intelligence Upload API) and the Graph Security tiIndicators API, allowing custom or third-party feeds to be pushed programmatically. Option A (Syslog from a firewall) is not a threat intelligence source; it is raw log telemetry ingested via the Syslog/CEF connector for detection, not curated indicator data. Option E (Azure Policy) is a governance/compliance service for enforcing resource configurations and has no role in ingesting threat intelligence indicators.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Syslog from a firewall
Why it's wrong here
Raw syslog from a firewall is unprocessed log data, not a threat intelligence feed; Sentinel ingests it as a log source for analytics rules, not as indicator-of-compromise enrichment. Syslog suits custom detection queries, whereas threat intelligence requires structured STIX or TAXII indicator feeds.
- ✓
Microsoft Threat Intelligence feed
Why this is correct
Microsoft Threat Intelligence feed is natively integrated with Microsoft Sentinel, providing curated indicators of compromise from Microsoft's global telemetry. It satisfies the stem's ingestion requirement without custom connectors, unlike external feeds needing API configuration. This built-in source enriches threat hunting queries directly.
- ✓
TAXII server
Why this is correct
TAXII servers publish structured STIX threat indicators over a RESTful API, and Microsoft Sentinel's data connectors can poll a TAXII 2.0/2.1 endpoint to ingest those indicators continuously. This satisfies the stem's requirement for a valid ingested threat intelligence source, feeding watchlists and analytics rules for hunting.
- ✓
Custom threat intelligence via API
Why this is correct
Microsoft Sentinel exposes a threat intelligence upload API, letting analysts push custom STIX indicators programmatically. This satisfies the stem's requirement for a valid ingestion source, covering bespoke or internal indicators that commercial feeds do not supply.
- ✗
Azure Policy
Why it's wrong here
Azure Policy enforces governance rules and audits resource compliance; it produces no indicators of compromise or adversary data for Sentinel's threat intelligence connectors. It is tempting because it feeds Sentinel, but as configuration-compliance telemetry rather than intel. It would be correct when enforcing organisational standards across Azure subscriptions.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.