Courseiva
Perform threat hunting →mediumMultiple Select

SC-200 Perform threat hunting Practice Question

Which TWO actions are valid when performing threat hunting in Microsoft Sentinel using hunting queries? (Choose two.)

⚠ Common exam trap

SC-200 often tests the confusion between hunting queries and analytics rules, so candidates must remember that hunting queries are manual and cannot be scheduled or alert automatically.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Bookmark specific rows of results for later investigation.

Option A is correct because Microsoft Sentinel hunting queries return results in Logs, and an analyst can select rows and create bookmarks to preserve those findings and pivot them into an investigation. Option B is correct because a hunting query can be converted into a custom analytics rule, which then runs on a schedule and generates incidents/alerts for ongoing detection. Option C is not valid because hunting queries are ad hoc/manual by design; scheduling and alerting are functions of analytics rules, not the hunting query itself. Option D is likewise not valid for hunting queries, since automatic alerting on query results requires an analytics rule. Option E is not a built-in hunting-query action; exporting to Azure Blob Storage would require separate tooling or workflows, not a native hunting query operation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Bookmark specific rows of results for later investigation.

    Why this is correct

    Bookmarking preserves specific result rows, together with their entities and timestamps, so they can be revisited, tagged and investigated later. This satisfies the valid hunting action of retaining evidence from query output rather than losing it when the results grid is refreshed.

  • ✓

    Create a custom detection rule based on a hunting query.

    Why this is correct

    A hunting query can be promoted directly into a custom analytics rule, converting a validated hypothesis into continuous scheduled detection. This satisfies the valid action of operationalising hunt findings, so newly discovered behaviour is alerted on automatically instead of requiring manual re-running.

  • ✗

    Schedule a hunting query to run every hour.

    Why it's wrong here

    Microsoft Sentinel hunting queries cannot be scheduled to run hourly; scheduling belongs to analytics rules, which run on a defined frequency. It is tempting because recurring execution suits continuous monitoring, and that is exactly when an analytics rule, not a hunting query, is the correct choice.

  • ✗

    Automatically trigger an alert when a hunting query returns results.

    Why it's wrong here

    Hunting queries are run manually or on demand; they do not natively raise alerts on result sets, so this action is invalid. It is tempting because alerting on query output mirrors what analytics rules do, and that is the correct mechanism when continuous detection is required rather than exploratory hunting.

  • ✗

    Export results directly to Azure Blob Storage.

    Why it's wrong here

    Hunting query results cannot be exported directly to Azure Blob Storage; they are reviewed in the portal, bookmarked, or used to create incidents or livestream sessions. It is tempting because long-term retention of large result sets suits blob storage, which is correct for exporting raw log data via data export rules instead.

Quick reference

Azure Blob Storage Tier Comparison

TierStorage CostRetrieval CostLatencyUse Case
HotHighestLowestImmediateActive data, frequent reads
CoolLowerHigherImmediateData accessed < once / month
ColdLower stillHigherImmediateData accessed < once / quarter
ArchiveLowestHighest + rehydration delayHoursLong-term compliance retention

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.