SC-200 - Manage a Security Operations Environment (41% of the exam) - Section 1.8

Configure Microsoft Sentinel analytics rules and anomalies, and map coverage with the MITRE ATT&CK matrix.

Configure scheduled analytics rules, near-real-time (NRT) rules, threat intelligence analytics rules, and machine learning analytics rules to surface incidents in Microsoft Sentinel. Use MITRE ATT&CK coverage mapping and anomaly rules to identify gaps in detection coverage and prioritise which tactics require additional analytics.

scheduled analytics rulesnear-real-time (NRT) rulesthreat intelligence analytics rulesmachine learning analytics rulesMITRE ATT&CK coverageanomalies in Microsoft Sentinel

Practice question for this objective

Free sampleManage a Security Operations Environmenthard

Leadership asks the SOC lead to show which MITRE ATT&CK tactics and techniques are currently covered by enabled detections in their Microsoft Sentinel workspace, and to identify gaps where no active analytics rule maps to a technique. Which Microsoft Sentinel capability presents this coverage view directly?

  • AThe Workbooks gallery, which visualises ingested log volume per connected data source over time
  • BThe MITRE ATT&CK coverage page, which colours the matrix by enabled analytics rules and hunting queries Correct
  • CThe Threat intelligence page, which lists imported indicators grouped by the tactic they relate to
  • DThe Entity behaviour page, which scores users and hosts against learned behavioural baselines
Know that the Microsoft Sentinel MITRE ATT&CK coverage page maps enabled analytics rules and hunting queries onto the matrix to reveal detection gaps. The MITRE ATT&CK page colours each technique in the matrix according to the active analytics rules and hunting queries that detect it, so the SOC can see covered tactics and pinpoint techniques with no associated detection. No other listed page renders this rule-to-technique mapping.

Why A is wrong: Workbooks chart operational metrics such as ingestion volume; while customisable, the gallery does not provide the built-in technique-by-rule coverage mapping that the request needs.

Why B is correct: The MITRE ATT&CK page in Sentinel overlays the matrix with the tactics and techniques covered by active rules and hunting queries, exposing coverage and gaps at a glance.

Why C is wrong: The threat intelligence page manages indicators of compromise, not detection coverage, so it cannot map enabled analytics rules onto the ATT&CK matrix to reveal gaps.

Why D is wrong: Entity behaviour focuses on per-entity risk from behavioural analytics; it does not enumerate which ATT&CK techniques your enabled rules detect or where coverage is missing.

See more SC-200 practice questions, answers explained.

Exam traps in Manage a Security Operations Environment

Answers that look right on this material and are not. Each one is a distractor from a different question in the SC-200 bank for this domain.

  • An NRT rule cannot declare MITRE ATT&CK tactics or techniques, so the detection will be absent from the coverage blade after conversion.

    Why it is wrong: NRT rules can declare tactics and techniques and do appear on the coverage blade, so this is a plausible but incorrect limitation.

  • The SecurityAlert table, where each anomaly is written as an alert

    Why it is wrong: SecurityAlert stores alerts produced by rules that raise alerts; the running anomaly rules are not raising alerts, so their scored output is not written there for the analyst to query.

  • Configure entity mappings on the rule so identities and hosts are extracted, which is what the coverage blade reads to draw the matrix.

    Why it is wrong: Entity mappings enrich alerts and incidents for investigation, but the coverage blade reads the declared tactics and techniques, not the mapped entities.

Examworthy is not affiliated with or endorsed by Microsoft. Original, blueprint-aligned practice material only.