Courseiva
Perform threat hunting →mediumMultiple Choice

SC-200 Perform threat hunting Practice Question

You are a security analyst using Microsoft Sentinel. You want to proactively search for signs of a specific threat actor known to use PowerShell encoded commands. Which hunting technique is most appropriate?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use a hunting query in the Microsoft Sentinel hunting blade to search for PowerShell encoded commands.

Hunting queries in Microsoft Sentinel allow proactive searching for suspicious patterns. Option D is correct because it directly aligns with the need to create a custom KQL query to detect encoded PowerShell commands in the hunting blade. Option A is incorrect because analytics rules trigger alerts after detection, not for proactive hunting. Option B is incorrect because a watchlist is used for correlation with known indicators, not proactive hunting. Option C is incorrect because UEBA identifies anomalies, not specific threat actor techniques.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create an analytics rule to trigger an alert when PowerShell encoded commands are detected.

    Why it's wrong here

    Analytics rules run continuously and raise alerts on matched events, which is detection rather than proactive hunting. Hunting demands interactive, hypothesis-driven queries across historical data. The option tempts because rules also use KQL against PowerShell events, but they automate monitoring instead of letting an analyst explore the encoded-command technique on demand.

  • ✗

    Create a watchlist of known malicious IPs and correlate with PowerShell events.

    Why it's wrong here

    Watchlists store reference data such as IPs or hashes for enrichment and correlation, not behavioural patterns like encoded PowerShell commands. They suit matching known indicators against events. Hunting a threat actor's PowerShell technique requires querying process command-line telemetry directly, which a static IP watchlist cannot express.

  • ✗

    Enable UEBA to detect anomalous PowerShell usage.

    Why it's wrong here

    UEBA baselines normal behaviour and flags statistical anomalies, so it detects deviations rather than a specific known technique such as encoded PowerShell commands. It suits identifying compromised accounts or insider drift. The option tempts because it also surfaces suspicious PowerShell, but it cannot target a defined threat actor's known command-line pattern.

  • ✓

    Use a hunting query in the Microsoft Sentinel hunting blade to search for PowerShell encoded commands.

    Why this is correct

    Hunting queries in the Microsoft Sentinel hunting blade let analysts proactively search logs for indicators such as PowerShell encoded commands, matching the requirement to seek out a known threat actor's techniques rather than wait for an alert.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.