SC-200 Perform threat hunting Practice Question
You are a security analyst using Microsoft Sentinel. You want to proactively search for signs of a specific threat actor known to use PowerShell encoded commands. Which hunting technique is most appropriate?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use a hunting query in the Microsoft Sentinel hunting blade to search for PowerShell encoded commands.
Hunting queries in Microsoft Sentinel allow proactive searching for suspicious patterns. Option D is correct because it directly aligns with the need to create a custom KQL query to detect encoded PowerShell commands in the hunting blade. Option A is incorrect because analytics rules trigger alerts after detection, not for proactive hunting. Option B is incorrect because a watchlist is used for correlation with known indicators, not proactive hunting. Option C is incorrect because UEBA identifies anomalies, not specific threat actor techniques.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create an analytics rule to trigger an alert when PowerShell encoded commands are detected.
Why it's wrong here
Analytics rules run continuously and raise alerts on matched events, which is detection rather than proactive hunting. Hunting demands interactive, hypothesis-driven queries across historical data. The option tempts because rules also use KQL against PowerShell events, but they automate monitoring instead of letting an analyst explore the encoded-command technique on demand.
- ✗
Create a watchlist of known malicious IPs and correlate with PowerShell events.
Why it's wrong here
Watchlists store reference data such as IPs or hashes for enrichment and correlation, not behavioural patterns like encoded PowerShell commands. They suit matching known indicators against events. Hunting a threat actor's PowerShell technique requires querying process command-line telemetry directly, which a static IP watchlist cannot express.
- ✗
Enable UEBA to detect anomalous PowerShell usage.
Why it's wrong here
UEBA baselines normal behaviour and flags statistical anomalies, so it detects deviations rather than a specific known technique such as encoded PowerShell commands. It suits identifying compromised accounts or insider drift. The option tempts because it also surfaces suspicious PowerShell, but it cannot target a defined threat actor's known command-line pattern.
- ✓
Use a hunting query in the Microsoft Sentinel hunting blade to search for PowerShell encoded commands.
Why this is correct
Hunting queries in the Microsoft Sentinel hunting blade let analysts proactively search logs for indicators such as PowerShell encoded commands, matching the requirement to seek out a known threat actor's techniques rather than wait for an alert.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.