SC-200 Manage a security operations environment Practice Question
Your organization uses Microsoft Defender XDR. You need to configure a custom detection rule that runs every hour and alerts when a specific process is executed on multiple devices within 10 minutes. Which type of rule should you create?
⚠ Common exam trap
Many candidates confuse 'custom detection rule' with 'advanced hunting query' or 'saved hunting query,' assuming any KQL-based alert is the same, but only custom detection rules provide the scheduled, time-windowed aggregation and alerting required for this scenario.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Custom detection rule
Custom detection rules in Microsoft Defender XDR allow you to define a query that runs on a schedule (e.g., every hour) and triggers an alert based on aggregation over a specified time window (e.g., 10 minutes). This rule type supports the exact requirement: detecting a specific process executed on multiple devices within a short timeframe, using the `make_set` or `dcount` aggregation functions in KQL.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Hunting query saved as a detection
Why it's wrong here
Hunting query saved as a detection is incorrect because saving a query simply stores the KQL for reuse; it does not impose a schedule, evaluate results against a threshold, or trigger an alert or incident. To become a detection, the query must be wrapped in a custom detection rule that defines a cadence and response actions. Thus, while you can save a hunting query and later convert it into a custom detection, the saved artifact itself is not a rule type.
- ✗
Behavioral rule
Why it's wrong here
Behavioral rule is incorrect because behavioral rules in Microsoft Defender XDR focus on detecting specific anomalous or malicious behaviors (such as credential access or lateral movement) using built-in analytics, not on running user-authored KQL queries on a schedule. These rules do not accept time-based aggregations from custom hunting queries, and they are not the mechanism for creating a scheduled detection from a KQL expression. The appropriate rule type for scheduled queries is a custom detection rule.
- ✓
Custom detection rule
Why this is correct
Custom detection rule is correct because this is the dedicated rule type in Microsoft Defender XDR that allows you to schedule an Advanced Hunting KQL query to run at defined intervals, apply time-based aggregations, and automatically generate alerts and incidents when thresholds are met. Custom detection rules provide full control over frequency, severity, and response actions, and they directly integrate with the incident management pipeline. This makes them the precisely designed mechanism for turning a recurring query into an active, automated detection.
- ✗
Advanced hunting query
Why it's wrong here
Advanced hunting query is incorrect because Advanced Hunting is an interactive data exploration tool, not a detection rule type. A query entered in the Advanced Hunting portal is run once when you execute it, and it does not persist on a schedule or produce alerts by itself. While you can reuse or share an Advanced Hunting query by saving it, saving does not confer the scheduling and alerting capabilities that are exclusive to custom detection rules.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.