SC-200 Manage a security operations environment Practice Question
Your organization uses Microsoft Sentinel and has deployed multiple analytics rules. You need to evaluate the effectiveness of these rules by identifying which rules generate the most incidents and have the highest false positive rate. What should you use?
⚠ Common exam trap
Many candidates confuse the Hunting view (used for proactive searches) with the Incidents view (used for post-detection analysis), or assume the MITRE ATT&CK view provides rule-level performance metrics when it only maps incidents to attack techniques.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Incidents view in Microsoft Sentinel filtered by analytics rule
The Incidents view in Microsoft Sentinel allows you to filter incidents by analytics rule, enabling you to see the count of incidents generated per rule and assess their effectiveness. By reviewing the incident details, you can identify which rules produce the most incidents and, by analyzing the closed or resolved incidents, determine the false positive rate. This directly addresses the requirement to evaluate rule effectiveness based on incident volume and false positives.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Incidents view in Microsoft Sentinel filtered by analytics rule
Why this is correct
The Incidents view in Microsoft Sentinel is the dedicated operational workspace where alerts are grouped into incidents and linked back to their originating analytics rule. By filtering on a specific rule, you can directly see how many incidents that rule generated, their current status (new, in progress, resolved), and the classification assigned during triage, such as true positive, false positive, or benign positive. This is the authoritative place to review rule effectiveness because it reflects real detection outcomes and allows analysts to take corrective action on noisy or high-fidelity rules.
- ✗
Hunting view in Microsoft Sentinel
Why it's wrong here
The Hunting view is specifically designed for proactive, ad-hoc threat searching using Kusto Query Language (KQL) queries across your workspace, not for retroactively auditing the performance of deployed analytics rules. It does not aggregate or present the output of rule executions, such as incident counts or true/false positive classifications, and hunting queries are not tied to the schedule or logic of your analytics rules. While you could manually test a rule's detection logic in Hunting, the view lacks the operational metrics and incident context needed to evaluate how well a rule is actually performing in production.
- ✗
MITRE ATT&CK view in Microsoft Sentinel
Why it's wrong here
The MITRE ATT&CK view in Microsoft Sentinel displays which tactics and techniques are covered by your analytics rules, based on the technique identifiers configured in each rule, and is intended for gap analysis and coverage mapping. It does not show how a rule performs in terms of alert volume, incident generation, or classification outcomes, because its purpose is to illustrate detection breadth across the kill chain, not rule fidelity. Consequently, this view cannot answer questions about a rule's false-positive rate or whether its alerts are being triaged effectively, making it unsuitable for evaluating a specific rule's performance.
- ✗
Entity behavior analytics view in Microsoft Sentinel
Why it's wrong here
The Entity behavior analytics (UEBA) view is focused on profiling and analyzing behavioral anomalies for entities such as users, devices, and IP addresses using machine learning baselines, which is a separate analytical stream from scheduled analytics rule execution. It does not aggregate or present the incidents or alerts generated by your analytics rules, and it lacks any filtering by rule ID or rule name, so it cannot reveal detection outcomes like true/false positives or incident status. While UEBA can supplement threat detection, its behavioral scoring and timeline views are not connected to rule evaluation, so they provide no direct insight into whether a specific analytics rule is working correctly.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.