Courseiva
Perform threat hunting →easyMultiple Select

SC-200 Perform threat hunting Practice Question

Which TWO of the following are recommended practices when performing threat hunting in Microsoft Sentinel? (Choose 2)

⚠ Common exam trap

The trap is picking 'rely on automated detections' or 'disable noisy rules' — both sound operationally convenient but contradict the proactive, hypothesis-driven nature of threat hunting.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create custom hunting queries based on hypothesis

Option A is correct because threat hunting in Microsoft Sentinel is hypothesis-driven: analysts write custom hunting queries in KQL (via the Hunting blade or Logs) to proactively search for evidence of the hypothesized adversary behavior rather than waiting for alerts. Option E is correct because watchlists let you upload and manage lists of high-value indicators (IPs, accounts, hashes, domains) that hunting queries can join against using the _GetWatchlist() function, keeping threat intel current without editing each query. Option B is wrong because relying solely on automated analytics rules is reactive detection, not proactive hunting, and misses threats the rules do not cover. Option C is wrong because disabling all built-in analytics rules removes valuable detections and creates blind spots instead of tuning noise. Option D is wrong because deleting log data destroys the historical evidence hunting depends on and undermines retention/compliance; query performance is addressed with table plans, summaries, and scoping, not data deletion.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Create custom hunting queries based on hypothesis

    Why this is correct

    Threat hunting is hypothesis-driven: analysts form a theory about adversary behaviour, then encode it as a custom query to surface matching activity. This satisfies the recommended practise of proactive, hypothesis-led hunting rather than relying solely on existing scheduled detections.

  • ✗

    Rely solely on automated detection rules

    Why it's wrong here

    Automated detection rules only surface activity matching pre-written analytics, so hunting requires proactive hypothesis-driven queries against raw logs to uncover threats those rules miss. It is tempting because automation reduces analyst effort, but that role suits continuous monitoring and alerting, not exploratory hunting for unknown adversary behaviour.

  • ✗

    Disable all built-in analytics rules to avoid noise

    Why it's wrong here

    Disabling built-in analytics rules removes the detections threat hunting depends on, so hunts lose their alerting foundation and coverage gaps appear. It is tempting because noisy rules do generate false positives, and tuning or suppressing individual rules is legitimate — but wholesale disabling is never a recommended hunting practise.

  • ✗

    Delete log data older than 30 days to improve query performance

    Why it's wrong here

    Deleting logs removes the historical telemetry threat hunters query to reconstruct adversary activity, undermining hunting and incident investigation. It is tempting because trimming data reduces ingestion cost and speeds queries, but that role suits retention-policy tuning for low-value noise, not discarding security events that Microsoft Sentinel analytics and hunting queries depend on.

  • ✓

    Use watchlists to maintain high-value indicators for matching

    Why this is correct

    Watchlists store curated, high-value indicators such as IPs, accounts or hashes that queries can join against. This satisfies the recommended practise of enriching hunts with organisational context, letting analysts match telemetry against known-suspicious entities without hardcoding values into each query.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.