Courseiva
Perform threat hunting →easyMultiple Select

SC-200 Perform threat hunting Practice Question

Which TWO techniques are commonly used in threat hunting to identify potential malicious activity? (Choose two.)

⚠ Common exam trap

The trap is selecting 'wait for alerts' or 'block traffic' — both are operational security activities, not threat hunting techniques, and distract from the proactive, investigative nature of hunting.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Searching for known indicators of compromise (IoCs).

Option A is correct because threat hunting commonly begins with searching for known indicators of compromise (IoCs) such as malicious IP addresses, file hashes, domain names, and registry keys, which can reveal evidence of past or ongoing attacks. Option C is correct because analyzing anomalies in baseline behavior—deviations from normal user, endpoint, or network activity—helps hunters uncover unknown or evasive threats that signature-based tools may miss. Disabling security controls (B) is not a threat-hunting technique; it weakens defenses and is unsafe. Waiting for alerts from automated detection tools (D) is reactive monitoring rather than proactive hunting. Automatically blocking all suspicious traffic (E) is a prevention/response action, not an investigative hunting method.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Searching for known indicators of compromise (IoCs).

    Why this is correct

    Searching for known indicators of compromise lets hunters match observed artefacts — file hashes, IP addresses, domains — against threat intelligence. This reactive technique rapidly confirms whether known malicious infrastructure or payloads are present in the environment, satisfying one recognised threat hunting methodology.

  • ✗

    Disabling security controls to observe attacker behavior.

    Why it's wrong here

    Disabling controls weakens the environment and manufactures the very activity being hunted, invalidating findings rather than identifying malicious behaviour. It is tempting because controlled observation of attacker tradecraft is legitimate in isolated sandboxes or cyber-range exercises, not production threat hunting.

  • ✓

    Analyzing anomalies in baseline behavior.

    Why this is correct

    Analysing anomalies in baseline behaviour establishes what normal activity looks like, then flags statistically significant deviations such as unusual login times, volumes, or process lineages. This hypothesis-driven technique surfaces previously unknown threats that signature-based indicator matching would miss entirely.

  • ✗

    Waiting for alerts from automated detection tools.

    Why it's wrong here

    Threat hunting is a proactive, hypothesis-driven search through telemetry for activity that automated detections missed; waiting for alerts is reactive monitoring, not hunting. It is tempting because alert triage feels adjacent to hunting, yet it depends on existing detection rules rather than analyst-led queries.

  • ✗

    Automatically blocking all suspicious traffic.

    Why it's wrong here

    Threat hunting is a detective, hypothesis-driven activity; automatic blocking is a preventive control that acts before analysis and yields no hunting telemetry. It is tempting because containment matters during active incidents, where automated blocking of confirmed malicious traffic is the right response.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.