hardMultiple ChoiceObjective-mapped
SC-100 Practice Question: A global organization uses Microsoft Sentinel for…
A global organization uses Microsoft Sentinel for SIEM and Microsoft Defender for Cloud for cloud security posture management. The security team notices that critical alerts from Azure Active Directory Identity Protection are not triggering automated response playbooks in Sentinel. The team needs to ensure that all high-severity Identity Protection risk detections automatically create incidents in Sentinel and trigger a playbook to block the user. What should the team configure?
⚠ Common exam trap
Test-takers frequently confuse simply enabling a data connector (which only ingests data) with the separate requirement of creating an incident creation rule to transform those alerts into actionable incidents, leading them to pick Option B or D.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable the Identity Protection data connector and create a Microsoft Security incident creation rule for Identity Protection.
To have Identity Protection risk detections automatically create incidents in Microsoft Sentinel and trigger a playbook, you must first enable the Identity Protection data connector (which brings the alerts into Sentinel) and then create a Microsoft Security incident creation rule specifically for Identity Protection. This rule ingests the alerts as security incidents, and you can attach an automation rule to run a playbook (e.g., to block the user) when a high-severity incident is created. Without the incident creation rule, the alerts would be ingested as raw events but not automatically turned into incidents.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enable the Identity Protection data connector and create a Microsoft Security incident creation rule for Identity Protection.
Why this is correct
This is the correct, complete configuration for Microsoft Sentinel. The Identity Protection data connector ingests risk detections and alerts from Azure AD Identity Protection into Sentinel, and the Microsoft Security incident creation rule for Identity Protection is the required analytics rule that automatically generates incidents from those ingested alerts. Without this analytics rule, the alerts remain as raw events with no incident lifecycle, so enabling both together satisfies the requirement to create incidents automatically.
- ✗
Enable the Azure Active Directory Identity Protection data connector in Sentinel.
Why it's wrong here
Enabling the Azure Active Directory Identity Protection data connector in Sentinel is a necessary first step, but it is insufficient on its own. The connector only ingests the raw alert data into the workspace; it does not create security incidents. To generate incidents, you must also configure a separate Microsoft Security incident creation rule that defines how those connector alerts are grouped and turned into actionable incidents.
- ✗
Configure diagnostic settings on Azure AD to stream logs to Sentinel and create a playbook automation rule.
Why it's wrong here
Configuring diagnostic settings on Azure AD streams sign-in and audit logs to a Log Analytics workspace, which is not the same as connecting Identity Protection alerts, and it does not directly yield incidents. A playbook automation rule is designed to invoke automated response actions, not to create incidents from Identity Protection alerts. This option also omits the crucial analytics rule (the Microsoft Security incident creation rule) required to generate incidents, so it fails the stated requirement.
- ✗
Configure the Identity Protection connector with the 'Create incidents' toggle enabled.
Why it's wrong here
The 'Create incidents' toggle is not a property of the Identity Protection data connector; it exists as an option on the analytics rule (specifically the Microsoft Security incident creation rule) that processes the connector's alerts. Configuring a non-existent toggle on the connector would have no effect and still leave you without any incident creation. You must enable the connector and then configure the analytics rule with its incident creation option enabled to actually generate incidents.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-100 question from scratch — 208 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.