Courseiva
Perform threat hunting →easyMultiple Select

SC-200 Indicators of Compromise (IOCs) Practice Question

Which TWO are common techniques used during threat hunting to identify suspicious behavior in Microsoft Defender XDR?

⚠ Common exam trap

The trap is confusing threat hunting with other security operations like vulnerability scanning or antivirus updates; candidates must recognize that threat hunting is proactive and intelligence-driven, not routine maintenance.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Searching for known indicators of compromise (IOCs).

Option B is correct because threat hunting in Microsoft Defender XDR commonly begins with searching for known indicators of compromise (IOCs) such as malicious file hashes, IP addresses, domains, or URLs using advanced hunting queries (KQL) against tables like DeviceNetworkEvents and DeviceFileEvents. Option C is correct because applying anomaly detection models to user behavior — for example, identifying unusual sign-in patterns or atypical activity via Microsoft Defender for Identity and Microsoft Sentinel UEBA — is a core proactive hunting technique for uncovering threats that signature-based detection misses. Option A is not a hunting technique; updating antivirus signatures is a routine preventive maintenance task performed by Defender Antivirus, not an investigative method. Option D is incorrect because configuring mail flow rules in Exchange Online is an administrative mail-handling action, not a threat-hunting technique. Option E is incorrect because vulnerability scans identify unpatched weaknesses rather than actively hunting for suspicious or malicious behavior in Defender XDR telemetry.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Updating antivirus signatures.

    Why it's wrong here

    Signature updates are a preventive maintenance task performed automatically by Defender antivirus; they harden endpoints rather than surface latent adversary activity. Threat hunting instead queries advanced hunting tables such as DeviceProcessEvents for anomalous behaviour not yet flagged by signatures.

  • ✓

    Searching for known indicators of compromise (IOCs).

    Why this is correct

    Matching known IOCs — file hashes, domains, IP addresses — against telemetry quickly flags artefacts already tied to confirmed campaigns. It is a core hunting technique because it converts threat intelligence into concrete queries across Defender XDR tables, surfacing compromised hosts without waiting for alerts.

  • ✓

    Applying anomaly detection models to user behavior.

    Why this is correct

    Anomaly detection models establish behavioural baselines for users and flag deviations such as unusual sign-in locations, volumes or times. This uncovers novel or low-and-slow activity that signature-based IOC matching misses, making it a standard proactive hunting technique within Microsoft Defender XDR.

  • ✗

    Configuring mail flow rules in Exchange Online.

    Why it's wrong here

    Mail flow rules act on message delivery — blocking, redirecting or tagging email — and are configured for transport policy, not investigation. They suit mail hygiene or data-loss scenarios; hunting suspicious behaviour relies on querying Defender XDR advanced hunting data for anomalous activity.

  • ✗

    Performing vulnerability scans on endpoints.

    Why it's wrong here

    Vulnerability scans enumerate missing patches and misconfigurations, producing a remediation backlog rather than evidence of active intrusion. They belong in vulnerability management programmes; hunting requires interrogating Defender XDR telemetry for suspicious process, network or identity events.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.