SC-100 Practice Question: Design security operations, identity, and compliance capabilities
A retail company is designing a security operations model in Microsoft Sentinel. The security team wants to detect suspicious activity in Microsoft Entra ID, including sign-ins from unfamiliar locations and changes to privileged roles, and they want the detections to be based on Microsoft's continuously updated threat intelligence rather than custom queries. Which Microsoft Sentinel feature should you recommend?
⚠ Common exam trap
The trap here is assuming a threat intelligence connector or a watchlist provides detection logic, when those supply enrichment data that analytics rules must consume.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Sentinel solutions for Microsoft Entra ID that include analytics rule templates
The requirement is for Microsoft-maintained, continuously updated identity detections rather than custom logic. Solutions in the Microsoft Sentinel content hub deliver connectors, analytics rule templates, and other artifacts for domains such as Microsoft Entra ID, and the templates cover the described identity scenarios. Custom rules, threat intelligence connectors, and watchlists are supporting components, not the source of maintained detections.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A threat intelligence platform connector that ingests indicators of compromise
Why it's wrong here
Threat intelligence connectors import indicators such as IP addresses and domains so they can be matched against logs. They enrich detection but do not themselves provide packaged identity detections for unfamiliar sign-in locations or privileged role changes. The team would still need analytics rules to act on the indicators, so this connector alone does not meet the requirement.
- ✗
A watchlist that contains the company's list of privileged role assignments
Why it's wrong here
Watchlists store reference data such as VIP lists or known privileged accounts that analytics rules can join against. They improve the accuracy of detections that already exist, but a watchlist is just data; it does not include detection logic, does not cover unfamiliar sign-in locations, and is not updated by Microsoft's threat intelligence.
- ✗
Custom analytics rules written with Kusto Query Language against the SigninLogs table
Why it's wrong here
Custom KQL analytics rules can detect the described activity, but they require the team to author and maintain the logic themselves and to update it as attack techniques change. The scenario explicitly asks for detections based on Microsoft's continuously updated intelligence rather than custom queries, so a hand-written rule set is the opposite of the requirement.
- ✓
Microsoft Sentinel solutions for Microsoft Entra ID that include analytics rule templates
Why this is correct
Solutions in the Microsoft Sentinel content hub package data connectors, analytics rule templates, workbooks, and playbooks for a specific domain such as Microsoft Entra ID. The analytics rule templates cover identity scenarios like unfamiliar sign-in locations and privileged role changes, and they are maintained by Microsoft, so the team gets up-to-date detections without authoring custom queries.
Go deeper
Related to this question
About these practice questions
This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.