Courseiva

SC-100 Practice Question: Design security operations, identity, and compliance capabilities

Your company uses Microsoft Sentinel for security operations. You need to design a solution to automatically respond to a confirmed ransomware incident by isolating affected devices and blocking malicious IPs. What should you use?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Sentinel automation rules with playbooks

Sentinel automation rules with playbooks (option B) is correct because automation rules in Microsoft Sentinel trigger Logic App playbooks in response to analytics rule alerts, and those playbooks can call Microsoft Defender for Endpoint APIs to isolate devices and update firewall/blocklist mechanisms to block malicious IPs. This directly matches the requirement for automated incident response to a confirmed ransomware incident. Azure Policy (A) is for enforcing governance and compliance on Azure resources, not for orchestrating incident response actions. Microsoft Defender for Cloud Apps (C) is a CASB for discovering and controlling cloud app usage, not for device isolation or IP blocking. Microsoft Intune (D) is for device management and compliance, not for automated security incident response workflows.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Azure Policy

    Why it's wrong here

    Azure Policy is a governance and compliance service that enforces rules on Azure resources by evaluating configuration states (e.g., resource tags, allowed locations) and auditing against defined policies. It cannot react to security incidents or trigger operational response actions like device isolation, because it operates on declarative compliance checks, not alert-driven automation. While it can enforce that required security controls (e.g., diagnostic settings) are present, it lacks the ability to invoke an external API- or connector-based workflow in response to a Sentinel incident.

  • ✓

    Sentinel automation rules with playbooks

    Why this is correct

    Sentinel automation rules are the native orchestration mechanism that listens for incident/alert triggers and invokes playbooks—workflows built on Azure Logic Apps. When an incident matches a rule condition, the automation rule runs a playground that can execute actions such as isolating a device via the Microsoft Defender for Endpoint connector, blocking an IP using a firewall connector, or opening a ticket in ITSM systems. This is the correct answer because it provides a first-party, built-in path that directly links Sentinel's alert pipeline to automated response actions via Log Apps' rich connector ecosystem, with no custom scripting required.

  • ✗

    Microsoft Defender for Cloud Apps

    Why it's wrong here

    Microsoft Defender for Cloud Apps (MSCA) is focused on cloud access security broker (CASB) capabilities—providing visibility, controlling shadow IT, and enforcing conditional access policies on cloud apps. Its native automation is limited to cloud-app-level responses such as 'session control' or 'file quarantine' (e.g., for apps like SharePoint), and it does not natively automate response actions for on-premises devices like isolating an endpoint. While MSCA can send alerts to Sentinel for correlation, it is not a response engine that Sentinel automation rules to perform device-level isolation, making it an incorrect choice for this scenario.

  • ✗

    Microsoft Intune

    Why it's wrong here

    Microsoft Intune is an endpoint management solution that handles device compliance, configuration profiles, and remote actions like wipe, lock, or retire—but it does not natively subscribe to Sentinel alert triggers or provide built-in automation rules for incident response. To achieve automated device isolation via Intune from a Sentinel incident, you would need to build a custom Logic App or PowerShell script that calls Microsoft Graph API endpoints for Intune actions, which is not an out-of-the-box capability from Sentinel's automation rule interface. Intune's strength is device lifecycle management, not real-time, alert-driven security orchestration, so it cannot be used directly without significant custom integration.

About these practice questions

Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.