Courseiva
Perform threat hunting →hardMultiple Select

SC-200 Perform threat hunting Practice Question

Which TWO of the following are valid approaches to perform threat hunting using Microsoft Sentinel? (Choose two.)

⚠ Common exam trap

Candidates often confuse automated detection rules (like Fusion) or response automation (like playbooks) with the manual, iterative process of threat hunting, which requires interactive querying and live monitoring rather than passive alerting.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Using the Hunting blade and Livestream

The Hunting blade in Microsoft Sentinel provides a dedicated interface for proactive threat hunting, allowing analysts to run KQL queries and pivot through results. Livestream extends this by enabling continuous, real-time query execution against incoming data, which is essential for detecting patterns that evolve over minutes or hours. Both features are explicitly designed for iterative, hypothesis-driven threat hunting rather than automated detection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Using Fusion analytics rule

    Why it's wrong here

    Fusion analytics rules in Microsoft Sentinel are correlation-based detection engines that automatically combine alerts and signals from multiple sources (e.g., Microsoft Entra ID, Microsoft Defender) to create high-fidelity incidents using machine learning. They are a purely reactive detection mechanism that runs continuously in the background, not an interactive hunting method. Threat hunting, by contrast, is a proactive, analyst-driven search through raw logs to find unknown threats, so Fusion rules serve a completely different purpose.

  • ✓

    Using the Hunting blade and Livestream

    Why this is correct

    The Hunting blade in Microsoft Sentinel provides a centralized interface containing built-in hunting queries mapped to MITRE ATT&CK techniques, allowing analysts to run predefined KQL searches and pivot on suspicious results. Livestream is a complementary feature that creates an ongoing KQL query session over live ingested data, presenting real-time results that update as logs flow in, with optional alerts on each result. This combination is a valid hunting approach because it directly supports proactive, iterative, and continuous investigation of workspace data.

  • ✗

    Using Automation rules to trigger playbooks

    Why it's wrong here

    Automation rules are Sentinel's tool for orchestrating incident response—they define triggers, conditions, and actions such as assigning severity, closing incidents, or invoking playbooks for threat mitigation. They execute only after an incident or alert is created, making them fundamentally reactive responders rather than hunting tools. Hunting is an active, data-centric exploration process, whereas automation rules manage the lifecycle of alerts and incidents that have already been generated by detection mechanisms.

  • ✓

    Using KQL queries in the Logs blade

    Why this is correct

    The Logs blade in Microsoft Sentinel (also known as the Log Analytics interface) gives analysts direct access to all raw log tables in the workspace, enabling fully custom KQL queries with joins, filtering, time-based pivots, and statistical aggregation. This allows threat hunters to test hypotheses, investigate entities, and discover patterns of suspicious behavior that scheduled queries or analytics rules may miss. As a primary interface for ad-hoc querying, the Logs blade is a valid approach to manual, iterative threat hunting.

  • ✗

    Using Azure Policy to enforce compliance

    Why it's wrong here

    Azure Policy is an Azure control-plane service that enforces governance and compliance by auditing or denying resource configuration modifications, such as requiring specific tags, restricting resource locations, or ensuring standard SKUs. It does not ingest or analyze log data from workloads, nor does it have any visibility into user, entity, or network activity relevant to security threats. Therefore, using Azure Policy cannot support threat hunting in Microsoft Sentinel—it addresses infrastructure compliance, not data-plane detection or investigation.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.