SC-200 Perform threat hunting Practice Question
Which TWO techniques are commonly used in threat hunting to identify potential malicious activity? (Choose two.)
⚠ Common exam trap
The trap is selecting 'wait for alerts' or 'block traffic' — both are operational security activities, not threat hunting techniques, and distract from the proactive, investigative nature of hunting.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Searching for known indicators of compromise (IoCs).
Option A is correct because threat hunting commonly begins with searching for known indicators of compromise (IoCs) such as malicious IP addresses, file hashes, domain names, and registry keys, which can reveal evidence of past or ongoing attacks. Option C is correct because analyzing anomalies in baseline behavior—deviations from normal user, endpoint, or network activity—helps hunters uncover unknown or evasive threats that signature-based tools may miss. Disabling security controls (B) is not a threat-hunting technique; it weakens defenses and is unsafe. Waiting for alerts from automated detection tools (D) is reactive monitoring rather than proactive hunting. Automatically blocking all suspicious traffic (E) is a prevention/response action, not an investigative hunting method.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Searching for known indicators of compromise (IoCs).
Why this is correct
Searching for known indicators of compromise lets hunters match observed artefacts — file hashes, IP addresses, domains — against threat intelligence. This reactive technique rapidly confirms whether known malicious infrastructure or payloads are present in the environment, satisfying one recognised threat hunting methodology.
- ✗
Disabling security controls to observe attacker behavior.
Why it's wrong here
Disabling controls weakens the environment and manufactures the very activity being hunted, invalidating findings rather than identifying malicious behaviour. It is tempting because controlled observation of attacker tradecraft is legitimate in isolated sandboxes or cyber-range exercises, not production threat hunting.
- ✓
Analyzing anomalies in baseline behavior.
Why this is correct
Analysing anomalies in baseline behaviour establishes what normal activity looks like, then flags statistically significant deviations such as unusual login times, volumes, or process lineages. This hypothesis-driven technique surfaces previously unknown threats that signature-based indicator matching would miss entirely.
- ✗
Waiting for alerts from automated detection tools.
Why it's wrong here
Threat hunting is a proactive, hypothesis-driven search through telemetry for activity that automated detections missed; waiting for alerts is reactive monitoring, not hunting. It is tempting because alert triage feels adjacent to hunting, yet it depends on existing detection rules rather than analyst-led queries.
- ✗
Automatically blocking all suspicious traffic.
Why it's wrong here
Threat hunting is a detective, hypothesis-driven activity; automatic blocking is a preventive control that acts before analysis and yields no hunting telemetry. It is tempting because containment matters during active incidents, where automated blocking of confirmed malicious traffic is the right response.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.