Courseiva
Perform threat hunting →mediumMultiple Select

SC-200 Perform threat hunting Practice Question

Which TWO of the following are valid methods to initiate a threat hunting session in Microsoft Sentinel?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Start from a specific detection rule

Starting from a specific detection rule and using a predefined hunting query are both valid methods. Live mode is not a feature; custom analytics rules are for detection, not hunting; and watchlists are used for enrichment, not for initiating hunting.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a custom analytics rule

    Why it's wrong here

    Custom analytics rules are scheduled detection mechanisms that generate alerts and incidents based on a predefined KQL query, not interactive hunting tools. Because they run on a fixed schedule with explicit detection logic, they cannot be used to initiate an ad-hoc hunting query in the Hunting blade. To hunt, you need a query you run manually; an analytics rule is the end product of a detection workflow, not a starting point for exploration.

  • ✗

    Import a watchlist as a hunting query

    Why it's wrong here

    Importing a watchlist has no relation to initiating a hunt: a watchlist is a static set of data (such as IP addresses or usernames) stored in Microsoft Sentinel for enrichment, not a KQL query file. You can reference watchlists inside a hunting query using the _GetWatchlist function to correlate data, but the watchlist itself cannot be executed as a query. Therefore, importing one cannot begin a hunting session.

  • ✓

    Start from a specific detection rule

    Why this is correct

    Starting from a detection rule is a valid method because the rule's underlying KQL query exposes the same log data used for detection and can be run interactively in the Logs or Hunting blade to explore broader patterns. For example, you can right-click a rule, select 'Run query' to see its results, then refine the query to look for related activity. This pivot from a deterministic detection to a broader investigation is a recognized hunting entry point in Microsoft Sentinel.

  • ✓

    Use a predefined hunting query from the Microsoft Sentinel content hub

    Why this is correct

    The Microsoft Sentinel content hub offers out-of-the-box hunting queries developed by Microsoft and the security community, which you can install and run directly from the Hunting blade. These predefined KQL queries are purpose-built to initiate hunts for specific attack techniques, such as credential access or lateral movement. Using them is a standard, supported way to start hunting without writing a query from scratch.

  • ✗

    Enable live mode on a hunting query

    Why it's wrong here

    There is no 'live mode' feature for hunting queries in Microsoft Sentinel; all hunting queries are executed on demand in the Hunting blade or Logs. You can schedule a query by converting it into an analytics rule, but that turns it into a detection rule, not a live-mode hunt. Because hunting is an interactive, iterative process, the option name itself is invalid.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.