SC-200 - Perform Threat Hunting (22% of the exam) - Section 3.2

Interpret threat analytics and analyse entity relationships using hunting graphs and Sentinel Graph in Microsoft Defender XDR.

Interpret threat analytics reports in Microsoft Defender XDR to understand active campaigns and assess organisational exposure across impacted assets. Use hunting graphs to visualise blast radius and Sentinel Graph to explore entity relationships and identify paths an attacker could use for lateral movement.

threat analytics in Microsoft Defender XDRhunting graphs including blast radiusSentinel Graph entity relationshipsexposure and impacted assets

Practice question for this objective

Free samplePerform Threat Huntingmedium

A security operations team opens a Microsoft Defender XDR threat analytics report for an active ransomware campaign and must prioritise remediation. They need to read two organisation-specific lists straight from the report, without writing any query: the assets that the campaign's techniques have already affected in the tenant, and the devices that are currently misconfigured or unpatched in ways that leave them open to those same techniques. Which TWO elements of the threat analytics report together surface both of these tenant-specific lists? Select TWO.

  • AThe impacted assets view, which lists the devices and identities in the organisation that the report's techniques have already affected, so already-hit assets are surfaced. Correct
  • BThe exposure and mitigations view, which lists the organisation's devices that remain misconfigured or unpatched against the report's techniques, so still-exposed devices are surfaced. Correct
  • CThe analyst report write-up, which describes the actor's techniques, indicators, and recommended detections in prose so the team can build their own hunting queries.
  • DThe related incidents view, which links the report to the cases the platform has already opened in the tenant for this campaign so triage can continue on real detections.
A Microsoft Defender XDR threat analytics report surfaces already-affected assets in the impacted assets view and still-vulnerable devices in the exposure and mitigations view. A threat analytics report separates what has already happened from what could still happen. The impacted assets view enumerates the organisation's devices and identities the campaign has already affected, while the exposure and mitigations view enumerates devices that remain misconfigured or unpatched against the same techniques, so both views are needed to read the two tenant-specific lists.

Why A is correct: The impacted assets view is the report element that names the organisation's devices and identities already touched by the campaign, giving the team the already-affected list.

Why B is correct: The exposure and mitigations view reports which devices still lack the recommended configurations and updates, giving the team the currently-exposed list to harden.

Why C is wrong: The analyst report explains the threat behaviour and detection guidance in narrative form, but it does not enumerate the tenant's specific affected or exposed assets.

Why D is wrong: Related incidents points to existing tenant cases for the campaign, which is useful, but it lists incidents rather than the affected-asset and exposed-device inventories.

See more SC-200 practice questions, answers explained.

Exam traps in Perform Threat Hunting

Answers that look right on this material and are not. Each one is a distractor from a different question in the SC-200 bank for this domain.

  • The device timeline, because it lists every event recorded on each device the account touched in chronological order, so it reveals the full set of resources the threat could propagate to next.

    Why it is wrong: The device timeline gives a per-device chronological event feed that is excellent for reconstructing what happened on one machine, but it does not model cross-entity relationships or forward propagation reach across mailboxes and cloud resources.

  • The number of devices flagged as exposed because they are missing the recommended mitigations for that campaign's techniques.

    Why it is wrong: Exposure counts measure preventive risk on unmitigated devices, which is tempting, but a device can be exposed without the threat ever having been detected in the tenant.

  • The Analyst report tab, because it contains the detailed write-up of the campaign and therefore enumerates the specific affected devices and identities present in the tenant for immediate triage.

    Why it is wrong: The Analyst report tab gives narrative context on attacker tradecraft and detection logic, but it is the same generic content for every tenant and does not list the organisation's own impacted devices or identities.

Examworthy is not affiliated with or endorsed by Microsoft. Original, blueprint-aligned practice material only.