Courseiva
Perform threat hunting →hardMultiple Select

SC-200 Perform threat hunting Practice Question

Which TWO actions are part of the threat hunting process in Microsoft Sentinel?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Creating custom hunting queries based on hypotheses.

Option A is correct because threat hunting in Microsoft Sentinel is hypothesis-driven: analysts write custom hunting queries (KQL) in the Hunting blade to proactively search ingested data for signs of compromise that existing detections may have missed. Option B is correct because bookmarks let hunters capture and preserve interesting query results, entities, and findings so they can be retained, shared, and later promoted into incidents or used to build new analytics rules. The other options are not part of the hunting process itself: C (data connectors) is a data ingestion/onboarding task, D (severity tuning) is detection tuning, and E (scheduled analytics rules) is detection engineering, all of which support but are distinct from proactive threat hunting.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Creating custom hunting queries based on hypotheses.

    Why this is correct

    Custom hunting queries operationalise a hypothesis by searching ingested log data for indicators that automated analytics have not flagged, satisfying the proactive, hypothesis-driven requirement of threat hunting in Microsoft Sentinel. Unlike scheduled analytics rules, which trigger alerts reactively, hunting queries are run on demand and their results can be promoted into detections.

  • ✓

    Using bookmarks to preserve interesting findings.

    Why this is correct

    Bookmarks preserve query results, entities and timestamps directly within a hunting session, letting analysts flag suspicious activity for later investigation or incident creation. This satisfies the threat hunting requirement to capture and retain noteworthy findings, rather than merely detecting or remediating them through automated analytics rules.

  • ✗

    Setting up data connectors to ingest logs.

    Why it's wrong here

    Data connector setup is onboarding and ingestion configuration, performed before hunting can occur, not part of the hunting process itself. It is tempting because hunting depends on ingested logs, and connector configuration would be correct when initially enabling a data source such as Microsoft Defender XDR or syslog.

  • ✗

    Fine-tuning the severity of analytical rules.

    Why it's wrong here

    Severity tuning adjusts existing analytics rules' alert prioritisation, which is detection engineering rather than threat hunting. It is tempting because both involve analytics rules, and it would be correct when reducing alert noise or aligning severities with organisational triage policy after rules are deployed.

  • ✗

    Configuring scheduled analytics rules.

    Why it's wrong here

    Configuring scheduled analytics rules is detection engineering that generates alerts, not threat hunting, which is proactive hypothesis-driven investigation. It is tempting because hunting often follows alerts, but scheduled rules would be the correct focus when building ongoing automated detection coverage rather than investigating a specific hypothesis.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.