SC-200 Manage a security operations environment Practice Question
Your security operations center uses Microsoft Sentinel and Microsoft Defender XDR. A new type of attack involves a user receiving a malicious email that triggers a macro, which then executes PowerShell to download a payload. You need to create a detection that correlates email, process creation, and network connection events from multiple Microsoft 365 Defender sources. What should you use?
⚠ Common exam trap
A common mix-up: candidates confuse the scope of custom detection rules in Microsoft 365 Defender, mistakenly believing they can cross-correlate multiple data sources, when in fact they are limited to a single table or entity type, whereas advanced hunting is designed for cross-table joins.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Advanced hunting in Microsoft 365 Defender
Advanced hunting in Microsoft 365 Defender is the correct choice because it allows you to write Kusto Query Language (KQL) queries that can join data across multiple tables from different Microsoft 365 Defender sources, such as EmailEvents, DeviceProcessEvents, and DeviceNetworkEvents. This enables correlation of the email receipt, macro-triggered PowerShell process creation, and subsequent network connection to a malicious IP or domain in a single query, which is exactly what the scenario requires.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Advanced hunting in Microsoft 365 Defender
Why this is correct
Advanced hunting is the Kusto Query Language (KQL)-based hunting environment natively embedded in Microsoft 365 Defender, allowing you to query raw, already-collected data across email, process, network, and identity tables in a single portal. Unlike Sentinel scheduled queries, it does not require you to first configure data connectors or build a Log Analytics pipeline, and it provides the full raw schema optimized for investigative hunting. This is the correct starting point for cross-domain hunting.
- ✗
Scheduled query rule in Microsoft Sentinel
Why it's wrong here
A scheduled query rule in Microsoft Sentinel requires that all email, process, and network logs first be ingested into a Log Analytics workspace via connectors, which adds cost, latency, and administrative overhead. While you could run a KQL query in Sentinel across these tables, Sentinel is not the native hunting interface for Microsoft 365 Defender data and is better suited for detection, alerting, and incident correlation. Therefore, it is technically possible but less efficient and not the correct answer for a direct hunting task.
- ✗
Custom detection rule in Microsoft 365 Defender
Why it's wrong here
A custom detection rule in Microsoft 365 Defender is an alerting rule built on top of an advanced hunting query; it schedules that query to run and generates alerts when you define suspicious patterns. For a one-off, interactive threat hunt, you would first use advanced hunting to run the query on demand, and only later, if you want continuous coverage, would you package it as a custom detection rule. Since the question asks for hunting action, the correct approach is advanced hunting itself, not a custom detection rule.
- ✗
Fusion rule in Microsoft Sentinel
Why it's wrong here
Fusion rules in Microsoft Sentinel are machine learning-based correlation rules that automatically combine related alerts from multiple security products into a single, high-fidelity incident. They do not accept custom KQL queries and give the analyst no direct ability to search across raw email, process, or network tables. Thus, choosing a Fusion rule would not satisfy the need to perform custom event correlation for hunting.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.