SC-200 - Manage a Security Operations Environment - Section 1.8

Configure Microsoft Sentinel analytics rules and anomalies, and map coverage with the MITRE ATT&CK matrix.

Configure scheduled analytics rules, near-real-time (NRT) rules, threat intelligence analytics rules, and machine learning analytics rules to surface incidents in Microsoft Sentinel. Use MITRE ATT&CK coverage mapping and anomaly rules to identify gaps in detection coverage and prioritise which tactics require additional analytics.

scheduled analytics rulesnear-real-time (NRT) rulesthreat intelligence analytics rulesmachine learning analytics rulesMITRE ATT&CK coverageanomalies in Microsoft Sentinel

Practice question for this objective

Free sampleManage a Security Operations Environmenthard

Leadership asks the SOC lead to show which MITRE ATT&CK tactics and techniques are currently covered by enabled detections in their Microsoft Sentinel workspace, and to identify gaps where no active analytics rule maps to a technique. Which Microsoft Sentinel capability presents this coverage view directly?

  • AThe Workbooks gallery, which visualises ingested log volume per connected data source over time
  • BThe MITRE ATT&CK coverage page, which colours the matrix by enabled analytics rules and hunting queries Correct
  • CThe Threat intelligence page, which lists imported indicators grouped by the tactic they relate to
  • DThe Entity behaviour page, which scores users and hosts against learned behavioural baselines
Know that the Microsoft Sentinel MITRE ATT&CK coverage page maps enabled analytics rules and hunting queries onto the matrix to reveal detection gaps. The MITRE ATT&CK page colours each technique in the matrix according to the active analytics rules and hunting queries that detect it, so the SOC can see covered tactics and pinpoint techniques with no associated detection. No other listed page renders this rule-to-technique mapping.

Why A is wrong: Workbooks chart operational metrics such as ingestion volume; while customisable, the gallery does not provide the built-in technique-by-rule coverage mapping that the request needs.

Why B is correct: The MITRE ATT&CK page in Sentinel overlays the matrix with the tactics and techniques covered by active rules and hunting queries, exposing coverage and gaps at a glance.

Why C is wrong: The threat intelligence page manages indicators of compromise, not detection coverage, so it cannot map enabled analytics rules onto the ATT&CK matrix to reveal gaps.

Why D is wrong: Entity behaviour focuses on per-entity risk from behavioural analytics; it does not enumerate which ATT&CK techniques your enabled rules detect or where coverage is missing.

See more SC-200 practice questions, answers explained.

More in this domain

Back to all Manage a Security Operations Environment objectives, or the SC-200 cert hub.

Examworthy is not affiliated with or endorsed by Microsoft. Original, blueprint-aligned practice material only.