Courseiva

SC-100 Practice Question: Design solutions that align with security best practices and priorities

Which THREE components are essential for implementing a successful SIEM strategy using Microsoft Sentinel?

⚠ Common exam trap

Candidates often confuse 'nice-to-have' features like Workbooks and Watchlists with 'essential' components, but Microsoft defines the three pillars of a successful SIEM strategy as data ingestion (connectors), detection (analytics rules), and automated response (automation rules).

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Automation rules

Data connectors (E) are essential because Microsoft Sentinel must first ingest telemetry from sources such as Microsoft 365, Azure, AWS, and third-party systems via connectors like the Azure Activity or Syslog connector before any detection or response can occur. Analytics rules (C) are essential because they correlate the ingested events and generate alerts/incidents based on scheduled, NRT, or Microsoft security rules, forming the core detection engine of the SIEM. Automation rules (A) are essential because they provide the orchestration and response layer, allowing Sentinel to automatically triage, assign, tag, or trigger playbooks on incidents to reduce response time. Workbooks (B) are valuable for visualization and reporting but are not required for the core detect-and-respond SIEM pipeline, and watchlists (D) are an optional enrichment feature for importing reference data such as IPs or VIP users, not a foundational component of a Sentinel SIEM strategy.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Automation rules

    Why this is correct

    Automation rules are central to Sentinel's SOAR capabilities because they let you define automated incident orchestration—such as assigning ownership, changing status, or running a playbook—when an alert is triggered or an incident is created. They close the gap between detection and response by turning analytics alerts into coordinated actions across Office 365, Microsoft Entra ID, and third-party systems. Without automation rules, alerts would require manual triage and response, reducing Sentinel to a passive monitoring tool rather than an active, automated security operations platform.

  • ✗

    Workbooks

    Why it's wrong here

    Workbooks are interactive dashboards built on Azure Resource Manager templates that visualize and query log data from the Log Analytics workspace. While they are extremely useful for executive reporting, threat hunting, and monitoring security posture, they are purely read-only consumers of data. They do not ingest logs, generate alerts, or execute automated responses, so removing them in no way breaks SIEM detection or SOAR orchestration. They are an operational enhancement, not a required component.

  • ✓

    Analytics rules

    Why this is correct

    Analytics rules are the detection engine of Microsoft Sentinel, enabling you to create scheduled or Microsoft Security rules that query ingested telemetry and generate alerts when suspicious conditions are met. Each rule defines the data source, frequency, lookback period, and entity mapping, and when triggered it creates an incident in Sentinel. Without these rules, raw log data would remain inert, with no automated mechanism to identify a security threat or initiate an incident. Therefore, analytics rules are indispensable for translating logs into actionable security detections.

  • ✗

    Watchlists

    Why it's wrong here

    Watchlists are optional collections of CSV data that you create to enrich and correlate with log data—such as lists of high-value assets, known malicious IPs, or privileged user accounts. You can reference them in analytics rules or hunting queries to add context, but they are not a prerequisite for any core Sentinel function. If omitted, Sentinel still fully ingests, detects, and responds to threats using live telemetry; they only improve accuracy and context for specific scenarios. Hence they are a value-add, but not essential to a baseline SIEM/SOAR implementation.

  • ✓

    Data connectors

    Why this is correct

    Data connectors are the fundamental ingestion layer of Microsoft Sentinel, bringing security telemetry—Windows events, Microsoft Entra ID sign-ins, Office 365 activity, AWS CloudTrail, and dozens of third-party products—into the unified Log Analytics workspace. Every analytics rule, hunting query, and automation action depends on this data being present and properly normalized into the schema. Without connectors, Sentinel would have zero log data to analyze, making both detection and response impossible, so they are the absolute foundation of the platform's operation.

About these practice questions

One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.