SC-100 Design security solutions for infrastructure Practice Question
Your company is migrating to a cloud-native security operations center (SOC) using Microsoft Sentinel. You need to design a solution that automatically investigates and remediates common incidents like brute-force attacks on Azure VMs. The solution should use playbooks triggered by analytics rules. Which Microsoft service should you use to create the playbooks, and what is the recommended authentication method?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Azure Logic Apps with managed identity
Azure Logic Apps is the recommended platform for Sentinel playbooks. Managed identity is the preferred authentication method because it avoids credential management and supports automation. Azure Automation is for runbooks, not playbooks. Service principal is possible but not recommended due to credential management.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Power Automate with user account
Why it's wrong here
Power Automate is designed for business process automation and isn't the execution engine for Microsoft Sentinel playbooks; Sentinel automation rules invoke Logic Apps workflows natively. Furthermore, authenticating with a user account means relying on interactive credentials that can expire, require MFA, and lack least-privilege access for runtime operations, making it unsuitable for autonomous security automation.
- ✗
Azure Automation with service principal
Why it's wrong here
Azure Automation runbooks can execute PowerShell or Python scripts, and a service principal provides non-interactive authentication; however, Sentinel playbooks are not implemented as Automation runbooks. Triggering a runbook from Sentinel would require custom webhooks, extra credential rotation for the service principal's secret or certificate, and still lacks the rich connector ecosystem and native incident trigger that Logic Apps provides.
- ✓
Azure Logic Apps with managed identity
Why this is correct
Azure Logic Apps is the underlying service for Sentinel playbooks, offering a native Microsoft Sentinel trigger that provides incident context to workflow actions. When a Logic Apps workflow uses a managed identity, it accesses Microsoft Entra ID-protected resources without storing secrets, simplifying credential management and enabling granular role assignments; this aligns with cloud-native security principles and is the recommended authentication model.
- ✗
Azure Functions with API key
Why it's wrong here
Azure Functions is a valid compute option for custom security logic, but it is not Sentinel's integrated playbook service, which expects Logic Apps workflows. An API key is a static secret that must be securely stored and rotated, offers no identity-based permissions, and can be accidentally exposed in headers or source control, making it far less secure and manageable than a managed identity in the Sentinel playbook context.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.