SC-200 Perform threat hunting Practice Question
Which TWO actions are part of the threat hunting process in Microsoft Sentinel?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Creating custom hunting queries based on hypotheses.
Option A is correct because threat hunting in Microsoft Sentinel is hypothesis-driven: analysts write custom hunting queries (KQL) in the Hunting blade to proactively search ingested data for signs of compromise that existing detections may have missed. Option B is correct because bookmarks let hunters capture and preserve interesting query results, entities, and findings so they can be retained, shared, and later promoted into incidents or used to build new analytics rules. The other options are not part of the hunting process itself: C (data connectors) is a data ingestion/onboarding task, D (severity tuning) is detection tuning, and E (scheduled analytics rules) is detection engineering, all of which support but are distinct from proactive threat hunting.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Creating custom hunting queries based on hypotheses.
Why this is correct
Custom hunting queries operationalise a hypothesis by searching ingested log data for indicators that automated analytics have not flagged, satisfying the proactive, hypothesis-driven requirement of threat hunting in Microsoft Sentinel. Unlike scheduled analytics rules, which trigger alerts reactively, hunting queries are run on demand and their results can be promoted into detections.
- ✓
Using bookmarks to preserve interesting findings.
Why this is correct
Bookmarks preserve query results, entities and timestamps directly within a hunting session, letting analysts flag suspicious activity for later investigation or incident creation. This satisfies the threat hunting requirement to capture and retain noteworthy findings, rather than merely detecting or remediating them through automated analytics rules.
- ✗
Setting up data connectors to ingest logs.
Why it's wrong here
Data connector setup is onboarding and ingestion configuration, performed before hunting can occur, not part of the hunting process itself. It is tempting because hunting depends on ingested logs, and connector configuration would be correct when initially enabling a data source such as Microsoft Defender XDR or syslog.
- ✗
Fine-tuning the severity of analytical rules.
Why it's wrong here
Severity tuning adjusts existing analytics rules' alert prioritisation, which is detection engineering rather than threat hunting. It is tempting because both involve analytics rules, and it would be correct when reducing alert noise or aligning severities with organisational triage policy after rules are deployed.
- ✗
Configuring scheduled analytics rules.
Why it's wrong here
Configuring scheduled analytics rules is detection engineering that generates alerts, not threat hunting, which is proactive hypothesis-driven investigation. It is tempting because hunting often follows alerts, but scheduled rules would be the correct focus when building ongoing automated detection coverage rather than investigating a specific hypothesis.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.