Courseiva
Perform threat hunting →mediumMultiple Choice

SC-200 Perform threat hunting Practice Question

Your organization uses Microsoft Sentinel with the Microsoft Defender XDR connector to ingest alerts and incidents from Defender for Endpoint, Defender for Office 365, and Defender for Identity. As a threat hunter, you want to proactively search for devices that may be communicating with known malicious IP addresses that have not yet triggered an alert. You have a list of known malicious IP addresses from an external threat intelligence feed. Which approach should you take to perform this hunt efficiently?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a Watchlist in Microsoft Sentinel containing the IP addresses, then write a KQL query in the Hunting blade that joins the Watchlist with DeviceNetworkEvents from Defender for Endpoint.

The most efficient approach. By creating a Watchlist in Microsoft Sentinel containing the list of known malicious IP addresses, you can write a KQL query in the Hunting blade that joins the Watchlist with the DeviceNetworkEvents table from Defender for Endpoint. This allows you to proactively query for any devices that have communicated with those IPs, even if no alert was generated. Option A is inefficient because Logic App is designed for automation and orchestration, not for ad-hoc hunting queries. Option C would require configuring a Threat Intelligence - TAXII connector with the specific feed, and the ThreatIntelligenceIndicator table may not contain the custom IP list. Option D is impractical for a large number of IPs and devices.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a Logic App that runs hourly and checks each IP against DeviceNetworkEvents, then creates incidents.

    Why it's wrong here

    Scheduled Logic App polling cannot query Sentinel's Log Analytics tables directly; it would need the Sentinel data connector or REST API, adding latency and cost. It is tempting as automation for incident creation, which suits playbook-driven response, not ad hoc hunting across DeviceNetworkEvents.

  • ✓

    Create a Watchlist in Microsoft Sentinel containing the IP addresses, then write a KQL query in the Hunting blade that joins the Watchlist with DeviceNetworkEvents from Defender for Endpoint.

    Why this is correct

    A Watchlist stores the external IP indicators as a reference table, letting a KQL query join them against DeviceNetworkEvents to surface devices contacting those addresses. This satisfies the requirement to hunt proactively across Defender for Endpoint telemetry without waiting for an alert.

  • ✗

    Use the ThreatIntelligenceIndicator table in Microsoft Sentinel, which automatically ingests the feed if you configure a Threat Intelligence - TAXII connector.

    Why it's wrong here

    The ThreatIntelligenceIndicator table stores indicators for matching, not device network telemetry; hunting devices communicating with those IPs requires querying DeviceNetworkEvents. It tempts because TAXII ingestion genuinely populates indicators, but the table alone cannot reveal endpoint connections, so no proactive hunt occurs.

  • ✗

    Manually add each IP address as a custom detection rule in Microsoft Sentinel for each device.

    Why it's wrong here

    Custom detection rules run scheduled queries and raise alerts; they do not provide interactive hunting across device network telemetry, and creating one per IP per device is unmanageable. It tempts because custom detections do automate alerting, but the task requires ad-hoc querying of DeviceNetworkEvents against the indicator list.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.