Courseiva

SC-100 Practice Question: Design security solutions for applications and data

Your company uses Microsoft Sentinel for security operations. You need to design a solution that automatically remediates a detected threat by blocking a malicious IP address on Azure Firewall. Which Microsoft Sentinel feature should you use?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

SOAR playbooks

Security Orchestration, Automation, and Response (SOAR) in Microsoft Sentinel uses playbooks to automate remediation actions like blocking IPs on Azure Firewall. Option A is wrong because analytics rules only generate alerts. Option B is wrong because workbooks visualize data. Option D is wrong because UEBA analyzes behavior but does not automate remediation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Analytics rules

    Why it's wrong here

    Analytics rules in Microsoft Sentinel are KQL-based query schedules that generate alerts and incidents when suspicious activity is detected. However, they are purely detection mechanisms — they do not execute any remediation or response actions themselves. To automate a response, an analytics rule must be paired with an automation rule that triggers a playbook; the analytics rule alone cannot take corrective steps.

  • ✗

    Workbooks

    Why it's wrong here

    Workbooks in Microsoft Sentinel are interactive canvas reports built on Azure Monitor Workbooks, used to visualize and analyze security data such as trends, anomalies, and investigation results. They provide situational awareness but do not perform any operational actions. Workbooks are read-only dashboards and cannot modify resources, execute mitigation steps, or interact with external systems for remediation.

  • ✓

    SOAR playbooks

    Why this is correct

    SOAR playbooks in Microsoft Sentinel are Azure Logic Apps–based workflows that automate response and remediation actions when triggered by an incident, alert, or automation rule. They can run actions like isolating a compromised VM, blocking an IP, or sending notifications, and they integrate with external tools like Microsoft Defender or third-party SOC platforms. Playbooks are the correct option because they provide active remediation, not just detection or visualization.

  • ✗

    User and Entity Behavior Analytics (UEBA)

    Why it's wrong here

    User and Entity Behavior Analytics (UEBA) in Microsoft Sentinel uses machine learning to baseline and detect anomalous user, host, and entity behaviors, such as impossible travel or unusual data exfiltration patterns. It surfaces these findings as alerts and insights, but UEBA itself does not perform any automated mitigation or response actions. You would need to attach a playbook or automation rule to act on UEBA detections.

About these practice questions

Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.