SC-200 Perform threat hunting Practice Question
Which THREE techniques would you use in Microsoft Sentinel to hunt for data exfiltration over DNS?
⚠ Common exam trap
SC-200 often tests whether candidates confuse DNS exfiltration with other exfiltration channels (HTTP, email), so options describing large transfers or email rules are distractors for a DNS-specific hunt.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Analyze DNS query logs for high volume or long subdomains
Option A is correct because DNS tunneling and exfiltration typically manifest as unusually high query volumes to a single domain or abnormally long subdomain labels that encode stolen data, so analyzing DNS query logs for these patterns is a core hunting technique in Microsoft Sentinel. Option C is correct because correlating DNS events with process creation events (for example via SecurityEvent 4688 or Sysmon Event ID 1) lets you identify which executable or script is generating the suspicious queries, distinguishing malicious tooling from legitimate resolvers. Option E is correct because ASIM (Advanced Security Information Model) DNS parsers normalize DNS logs from multiple sources into a common schema, enabling consistent anomaly detection and cross-source correlation across the workspace. Option B is not part of DNS exfiltration hunting since it focuses on large transfers to cloud storage IPs, which is HTTP/HTTPS exfiltration rather than DNS-based. Option D is also unrelated, as email forwarding rules address exfiltration via email (for example Exchange transport rules) and not DNS tunneling.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Analyze DNS query logs for high volume or long subdomains
Why this is correct
DNS tunneling commonly encodes data in the subdomain portion of a query name, so attackers craft unusually long subdomains (often 50+ characters) and generate a high query volume to a single authoritative domain. By analyzing DNS query logs for these patterns—such as label length, entropy, and query frequency per domain—you can directly detect the covert channel. This technique is effective because DNS traffic is frequently allowed through firewalls without deep inspection, making the logs the primary evidence of the exfiltration.
- ✗
Examine network traffic logs for large data transfers to known cloud storage IPs
Why it's wrong here
While examining network traffic logs for large data transfers to known cloud storage IPs might reveal exfiltration via HTTPS or other file-transfer protocols, it is not specific to DNS tunneling. DNS tunneling typically rides in small UDP packets that contain DNS queries and responses, which would not appear as large data transfers to cloud storage IPs. Therefore, this technique targets a different exfiltration vector and would completely miss the DNS-based covert channel that the question is asking you to detect.
- ✓
Correlate DNS events with process creation events to identify the process making queries
Why this is correct
Correlating DNS events with process creation events (e.g., Windows Event ID 4688 or Sysmon Event ID 1) allows you to attribute suspicious DNS queries to a specific executable, which is critical for identifying the source of DNS tunneling. If a seemingly benign process, such as a document reader, suddenly generates long subdomain queries, the process context alerts you to a potentially compromised or malicious binary. This is a valid hunting technique because DNS tunneling requires a process to initiate the queries, and process-level attribution helps distinguish legitimate queries from malicious ones.
- ✗
Review email forwarding rules for external domains
Why it's wrong here
Email forwarding rules that redirect messages to external domains are a known method for data exfiltration via SMTP, but they operate entirely outside the DNS protocol. Creating such a rule would not generate unusual DNS query patterns, because DNS is only used to resolve the external mail server's address at setup time, not continuously during rule-based forwarding. Since the question focuses on detecting DNS tunneling, this technique is irrelevant and would not identify the covert DNS-based channel described.
- ✓
Use ASIM DNS parsers to normalize DNS logs and detect anomalies
Why this is correct
The Advanced Security Information Model (ASIM) DNS parsers normalize DNS logs from multiple sources—such as Windows DNS Server, Corelight, and Bind—into a unified schema, enabling you to write consistent KQL queries across otherwise disparate log formats. This normalization simplifies anomaly detection, allowing you to efficiently hunt for indicators like high query rates, long subdomains, or unusual label entropy without manually reformatting each source. It is a recommended practice in Microsoft Sentinel because it reduces query complexity and improves the reliability and speed of your DNS-specific detection efforts.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.