nerdexam
Microsoft

SC-200 · Question #163

From which of the following can a SOC (Security Operation Center) analyst make a customized detection?

The correct answer is C. Advanced Hunting. Advanced hunting gives a choice to save the query as a detection, while Alert and Incident don't provide an option to save as a detection. https://docs.microsoft.com/en-us/microsoft-365/security/defender/advanced-hunting-query- results?view=o365-worldwide

Submitted by yaw92· Apr 18, 2026Configure protections and detections

Question

From which of the following can a SOC (Security Operation Center) analyst make a customized detection?

Options

  • AAlert
  • BIncident
  • CAdvanced Hunting
  • DRequest

How the community answered

(64 responses)
  • A
    2% (1)
  • B
    3% (2)
  • C
    95% (61)

Explanation

Advanced hunting gives a choice to save the query as a detection, while Alert and Incident don't provide an option to save as a detection. https://docs.microsoft.com/en-us/microsoft-365/security/defender/advanced-hunting-query- results?view=o365-worldwide

Topics

#Advanced Hunting#Custom Detection Rules#Threat Detection#Security Operations

Community Discussion

No community discussion yet for this question.

Full SC-200 Practice