Courseiva

SC-200 Manage a security operations environment Practice Question

Your Microsoft Defender XDR environment has an advanced hunting query that returns devices potentially affected by a known vulnerability. You want to create a custom detection rule that triggers an alert when more than 10 devices are affected. Which THREE steps are required?

⚠ Common exam trap

Many candidates confuse optional post-alert actions (like Power Automate flows or severity assignment) with the mandatory steps required to create a functional custom detection rule, leading them to select options C or D instead of focusing on the core rule creation steps (save query, set frequency/threshold, configure alert action).

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Set the rule frequency and threshold to trigger when the query returns more than 10 results.

Setting the rule frequency and threshold to trigger when the query returns more than 10 results directly implements the requirement to alert when more than 10 devices are affected. In Microsoft Defender XDR custom detection rules, the threshold condition is configured in the rule settings to evaluate the number of query results against a specified count, enabling precise alert triggering based on result volume.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Set the rule frequency and threshold to trigger when the query returns more than 10 results.

    Why this is correct

    In Microsoft Defender XDR custom detection rules, you must set both the rule frequency (how often the query runs, such as every hour) and the threshold (the number of results that triggers the rule) in the rule's settings. For this scenario, configuring the threshold to fire when the query returns more than 10 results ensures that only significant matches generate alerts, reducing false positives. This step is essential because without a defined frequency and threshold, the rule has no scheduling or triggering condition to act on.

  • ✓

    Configure the rule action to generate an alert in Microsoft Defender XDR.

    Why this is correct

    Configuring the rule action to generate an alert is the critical output mechanism of a custom detection rule; when the query results meet the threshold, this action creates an alert that appears in the Microsoft Defender XDR incidents queue. This alert includes metadata like the rule name, affected entities, and the underlying query results, enabling security analysts to investigate and respond. Without this action, the rule would only run silently without producing any actionable security signal.

  • ✗

    Assign the rule to a severity level.

    Why it's wrong here

    Severity is not a separate configuration step for the rule itself; it is an attribute of the alert that you define when you set up the rule's alert action. In the rule creation wizard, after choosing 'Generate alert', you assign a severity level (such as Low, Medium, High, or Critical) to that alert, along with other properties like title and tactics. Because severity is inherently part of the alert definition, treating it as an independent step would be redundant and inaccurate.

  • ✗

    Create a Power Automate flow to send an email when the rule triggers.

    Why it's wrong here

    Creating a Power Automate flow to send an email is an optional integration that goes beyond the standard custom detection rule workflow; the rule itself generates alerts directly within Microsoft Defender XDR, and email is not a required output. While you could build an automation to notify administrators of new alerts, that is a supplementary action that does not affect how the rule detects or alerts on threats. Including it as a necessary step would be incorrect because the rule functions fully without any external flow.

  • ✓

    Save the advanced hunting query as a custom detection rule.

    Why this is correct

    To operationalize an advanced hunting query as an automated detector, you must save it as a custom detection rule from the advanced hunting page by running the query and selecting 'Create detection rule'. This action converts the KQL query into a scheduled rule object that can be assigned a frequency, threshold, alert action, and entity mappings. Without this save operation, the query remains a one-off manual hunt and cannot produce recurring alerts, making this the foundational step in the process.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.