Courseiva

SC-100 Practice Question: Design security operations, identity, and compliance capabilities

A company uses Microsoft Sentinel for security operations. The SOC team needs to automatically respond to a specific type of incident involving a known malicious IP address. They want to create an automated response that blocks the IP at the firewall and creates a Teams notification. Which feature should they use?

⚠ Common exam trap

Many exam-takers confuse the role of analytics rules (which generate incidents) with automation rules (which respond to incidents), leading them to choose option D, thinking a scheduled query can directly execute actions, whereas it only creates alerts or incidents.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Automation rule with a playbook

Automation rules in Microsoft Sentinel allow you to trigger automated responses when incidents are created or updated. By associating a playbook (an Azure Logic Apps workflow) with the automation rule, you can execute actions such as blocking an IP at a firewall via a connector and posting a Teams notification. This directly meets the requirement for a two-step automated response triggered by a specific incident type.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    UEBA to detect anomalous behavior

    Why it's wrong here

    UEBA (User and Entity Behavior Analytics) in Microsoft Sentinel is designed to profile baseline behavior and detect anomalous activities—such as impossible travel, unusual sign-ins, or data exfiltration patterns—based on machine learning models. However, UEBA is purely a detection and investigation capability; it does not contain native mechanisms to execute automated responses, like isolating a user or initiating a playbook. When the goal is to automatically remediate a security incident, UEBA would only generate alerts or entities for later triage, leaving response actions to separate automation components.

  • ✗

    Watchlist to correlate IP addresses

    Why it's wrong here

    Watchlists in Microsoft Sentinel are collections of user-provided data (e.g., known malicious IPs, VIP user lists) that can be used to enrich, filter, or correlate events during querying and detection. They are powerful for threat intelligence and context, but they are static reference tables—they do not respond to threats or trigger any workflows on their own. Correlating IP addresses with a watchlist might help identify malicious traffic in an analytics rule, but the actual remediation still requires an automation rule or playbook to act on that correlation. Therefore, a watchlist is an enrichment tool, not a response mechanism.

  • ✓

    Automation rule with a playbook

    Why this is correct

    An automation rule in Microsoft Sentinel is the correct mechanism to automate response actions because it evaluates incident triggers or alert creation and then executes a set of configured actions, which can include running a playbook. Playbooks are built on Azure Logic Apps and can perform complex, orchestrated tasks like blocking a user, sending emails to stakeholders, opening a ticket, or gathering additional evidence—all without manual intervention. This directly fulfills the requirement to automatically respond to a security incident by turning detection results into immediate, actionable remediation steps.

  • ✗

    Analytics rule with scheduled query

    Why it's wrong here

    An analytics rule with a scheduled query is responsible for detecting threats by running KQL queries at regular intervals and generating alerts or incidents when suspicious patterns are found. While it can specify alert details, entity mapping, and even group events, it is not designed to execute response actions—it only creates the security signals. To automate a response, you would need to pair the analytics rule with an automation rule or a playbook; the analytics rule itself stops at the alert generation stage. Thus, selecting an analytics rule as the response mechanism is incorrect because it lacks any built-in action-taking capability.

About these practice questions

This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.