SC-200 Perform threat hunting Practice Question
Which TWO are valid methods for performing threat hunting in Microsoft Sentinel? (Choose two.)
⚠ Common exam trap
SC-200 often tests the distinction between hunting (proactive, query-driven) and detection/response (playbooks, watchlists, analytics rules), causing candidates to select response-oriented features as hunting methods.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Using the Hunting blade with built-in queries
Option B is correct because the Hunting blade in Microsoft Sentinel provides built-in, pre-designed hunting queries (based on KQL) that analysts can run across Log Analytics workspaces to proactively search for suspicious activity, which is a core threat-hunting method. Option D is correct because Microsoft Sentinel supports Jupyter notebooks integrated with MSTICpy, a Python library that enables advanced, customizable threat-hunting workflows such as querying logs, enriching data with threat intelligence, and visualizing results. Option A is not a hunting method but an automated incident-response capability (playbooks built on Logic Apps). Option C is incorrect because the MITRE ATT&CK dashboard/page in Sentinel is used for coverage mapping and understanding detections, not as a primary threat-hunting technique. Option E is incorrect because watchlists are used to store reference data (e.g., IPs, users) for correlation and can drive analytics rules, but creating alerts from watchlists is detection engineering, not threat hunting.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Using playbooks to respond to incidents
Why it's wrong here
Playbooks are automated response workflows triggered by analytics rules or incidents, so they remediate rather than hunt. They would be correct for automating containment actions such as isolating a host. Threat hunting in Microsoft Sentinel is performed through log queries and bookmarks in the Hunting blade.
- ✓
Using the Hunting blade with built-in queries
Why this is correct
The Hunting blade provides built-in, pre-built queries that run directly against your Log Analytics workspace, letting analysts pivot on entities and surface suspicious activity without authoring KQL from scratch. This satisfies the stem's requirement for a valid threat-hunting method in Microsoft Sentinel, complementing custom query development.
- ✗
Using the MITRE ATT&CK dashboard
Why it's wrong here
The MITRE ATT&CK dashboard in Microsoft Sentinel is a visualisation and coverage-mapping view of detected techniques, not a hunting interface for querying raw log data. It is useful for assessing detection coverage. Threat hunting is performed through log queries and bookmarks in the Hunting blade.
- ✓
Using Jupyter notebooks with MSTICpy
Why this is correct
Jupyter notebooks with MSTICpy extend Sentinel hunting beyond KQL queries, letting analysts run Python-based enrichment, anomaly detection and visualisation against Log Analytics data. This satisfies the stem's requirement for a valid hunting method, since MSTICpy is Microsoft's official threat-hunting library for Sentinel notebooks.
- ✗
Using watchlists to create alerts
Why it's wrong here
Watchlists store reference data, such as VIP lists or known-bad IPs, that analytics rules and queries can correlate against; they do not themselves create alerts. They would be correct for enriching detections with external data. Threat hunting is performed through log queries and bookmarks in the Hunting blade.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.