SC-200 Manage a security operations environment Practice Question
Your SOC uses Microsoft Defender XDR. You need to create a custom detection rule that triggers when a specific process is executed on multiple devices within an hour. Which feature should you use?
⚠ Common exam trap
Watch out — candidates often confuse Advanced Hunting (a query tool) with the custom detection rule feature (which uses Advanced Hunting queries as a foundation but is a distinct rule-creation capability), leading them to select Option A instead of D.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Defender XDR custom detection rule
Microsoft Defender XDR custom detection rules are built on top of Advanced Hunting and allow you to define conditions that trigger an alert when a specific process is executed across multiple devices within a defined time window (e.g., one hour). This feature is native to Defender XDR and does not require a separate SIEM like Sentinel, making it the correct choice for creating a detection rule that operates within the Defender XDR environment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Advanced hunting query
Why it's wrong here
Advanced hunting is an interactive KQL querying tool designed for manual, ad-hoc investigation of raw telemetry across Defender XDR tables. It does not run continuously or automatically generate alerts; results are returned immediately and are not persisted for future automated matching. To create an automated detection, you must save the query as a custom detection rule, which adds scheduling and alert generation.
- ✗
Microsoft Sentinel scheduled analytics rule
Why it's wrong here
Microsoft Sentinel scheduled analytics rules run within a Log Analytics workspace and are part of the broader SIEM architecture, not native Defender XDR. While they can ingest Defender XDR data via connectors, they execute in Sentinel and require separate licensing and workspace configuration. The question specifically asks for a custom detection in Defender XDR, so the native custom detection rule feature is the correct choice, not a Sentinel rule.
- ✗
Attack simulation training
Why it's wrong here
Attack simulation training is a security awareness feature in Microsoft 365 Defender that creates simulated phishing and password attacks to measure user susceptibility. It does not query telemetry or generate security alerts based on KQL logic, as it is intended for user education and behavior change. Consequently, it cannot be used to create a custom detection rule for malicious activity.
- ✓
Microsoft Defender XDR custom detection rule
Why this is correct
Custom detection rules in Microsoft Defender XDR allow you to author KQL queries against the platform's unified data model and run them on a schedule, generating alerts and incidents that flow into the XDR workflow. They are the native equivalent to Sentinel analytics rules but operate directly in Defender XDR, making them the correct method for creating a custom detection in this environment. You can even start from an existing advanced hunting query and save it as a custom detection rule.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.