hardMultiple SelectObjective-mapped
Key Components of a Security Operations Strategy According to Microsoft Best Practices
Which THREE of the following are key components of a security operations strategy according to Microsoft's best practices?
Quick Answer
The answer is post-incident activity (containment, eradication, recovery). This is correct because Microsoft’s security operations strategy, grounded in the NIST-based SOC maturity model, treats post-incident activity as the critical final phase that closes the loop on incident response—ensuring that threats are fully neutralized, systems are restored, and lessons learned are fed back into detection and analysis to reduce mean time to detect (MTTD). On the Microsoft Cybersecurity Architect exam, this question tests your understanding of the three core pillars in Microsoft’s framework: detection and analysis, response, and post-incident activity. A common trap is confusing post-incident activity with the response phase itself, but remember that response covers immediate actions like triage, while post-incident focuses on containment, eradication, and recovery. Memory tip: think “CER” for Contain, Eradicate, Recover—the final cleanup after the alarm has sounded.
⚠ Common exam trap
Watch out — candidates often confuse a specific Microsoft product (Sentinel) with a strategic component of the security operations lifecycle, leading candidates to select a tool name instead of the process phase it supports.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Detection and analysis
Detection and analysis is a core component of a security operations strategy because it defines how security events are identified, triaged, and investigated. Microsoft's NIST-based SOC maturity model emphasizes continuous monitoring and analytics (e.g., using Microsoft Sentinel analytics rules, UEBA, and threat intelligence) to reduce mean time to detect (MTTD). Without robust detection and analysis, an organization cannot effectively respond to threats.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Detection and analysis
Why this is correct
Detection and analysis is the core of security operations, identifying and investigating threats.
- ✓
Preparation including playbooks and training
Why this is correct
Preparation is a key phase in security operations, including developing playbooks and training analysts.
- ✗
Microsoft Sentinel deployment
Why it's wrong here
Microsoft Sentinel is a SIEM tool; its deployment is an implementation detail, not a component of the strategy.
- ✓
Post-incident activity (containment, eradication, recovery)
Why this is correct
Post-incident activity is a critical phase in security operations to contain and recover from incidents.
- ✗
Policy and standards development
Why it's wrong here
Policy development is part of governance, not the core security operations strategy components.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-100 question from scratch — 208 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SC-100
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A company is designing a security operations center (SOC) using Microsoft Sentinel. Which TWO of the following are best practices for managing incident response in Sentinel?
medium- A.Create multiple Sentinel workspaces for each incident type.
- ✓ B.Use automation rules and playbooks to automate common response actions.
- C.Manually classify all incidents to ensure accuracy.
- D.Use a single data connector for all log sources.
- ✓ E.Tag incidents with severity and status for better tracking.
Why B: Automation rules and playbooks in Microsoft Sentinel allow you to automate common incident response actions, such as triggering investigations, sending notifications, or running remediation scripts. This reduces manual effort, ensures consistent response, and accelerates mean time to respond (MTTR), which is a core best practice for SOC operations.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.