SC-200 - Perform Threat Hunting - Section 3.2

Interpret threat analytics and analyse entity relationships using hunting graphs and Sentinel Graph in Microsoft Defender XDR.

Interpret threat analytics reports in Microsoft Defender XDR to understand active campaigns and assess organisational exposure across impacted assets. Use hunting graphs to visualise blast radius and Sentinel Graph to explore entity relationships and identify paths an attacker could use for lateral movement.

threat analytics in Microsoft Defender XDRhunting graphs including blast radiusSentinel Graph entity relationshipsexposure and impacted assets

Practice question for this objective

Free samplePerform Threat Huntingmedium

A security operations team opens a Microsoft Defender XDR threat analytics report for an active ransomware campaign and must prioritise remediation. They need to read two organisation-specific lists straight from the report, without writing any query: the assets that the campaign's techniques have already affected in the tenant, and the devices that are currently misconfigured or unpatched in ways that leave them open to those same techniques. Which TWO elements of the threat analytics report together surface both of these tenant-specific lists? Select TWO.

  • AThe impacted assets view, which lists the devices and identities in the organisation that the report's techniques have already affected, so already-hit assets are surfaced. Correct
  • BThe exposure and mitigations view, which lists the organisation's devices that remain misconfigured or unpatched against the report's techniques, so still-exposed devices are surfaced. Correct
  • CThe analyst report write-up, which describes the actor's techniques, indicators, and recommended detections in prose so the team can build their own hunting queries.
  • DThe related incidents view, which links the report to the cases the platform has already opened in the tenant for this campaign so triage can continue on real detections.
A Microsoft Defender XDR threat analytics report surfaces already-affected assets in the impacted assets view and still-vulnerable devices in the exposure and mitigations view. A threat analytics report separates what has already happened from what could still happen. The impacted assets view enumerates the organisation's devices and identities the campaign has already affected, while the exposure and mitigations view enumerates devices that remain misconfigured or unpatched against the same techniques, so both views are needed to read the two tenant-specific lists.

Why A is correct: The impacted assets view is the report element that names the organisation's devices and identities already touched by the campaign, giving the team the already-affected list.

Why B is correct: The exposure and mitigations view reports which devices still lack the recommended configurations and updates, giving the team the currently-exposed list to harden.

Why C is wrong: The analyst report explains the threat behaviour and detection guidance in narrative form, but it does not enumerate the tenant's specific affected or exposed assets.

Why D is wrong: Related incidents points to existing tenant cases for the campaign, which is useful, but it lists incidents rather than the affected-asset and exposed-device inventories.

See more SC-200 practice questions, answers explained.

More in this domain

Back to all Perform Threat Hunting objectives, or the SC-200 cert hub.

Examworthy is not affiliated with or endorsed by Microsoft. Original, blueprint-aligned practice material only.