SC-100 Practice Question: Design security operations, identity, and compliance capabilities
Your organization deploys Microsoft Sentinel and wants to automatically respond to phishing emails reported by users. You need to recommend a solution that creates an incident in Sentinel and blocks the email sender in Exchange Online. What should you configure?
⚠ Common exam trap
SC-100 often tests the confusion between detection (analytics rules, UEBA) and response (automation rules + playbooks); candidates must pick the component that actually performs the blocking action.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an automation rule that runs a playbook when an incident is created.
Microsoft Sentinel automation rules trigger playbooks (Logic Apps) in response to incident creation. A playbook can call the Exchange Online connector to block the sender and can also update the Sentinel incident, providing the automated response the scenario requires. This is the standard SOAR pattern in Sentinel.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use a watchlist to store known phishing senders.
Why it's wrong here
Watchlists are passive reference tables used inside analytics rules for lookups and correlation; they cannot themselves initiate an automated response. Storing known phishing senders in a watchlist only provides data that a detection rule might later reference. Without an automation rule or playbook that consumes that watchlist data to invoke an Exchange Online block action, no mitigation occurs. Therefore, watchlists support detection and enrichment, not automatic response.
- ✓
Create an automation rule that runs a playbook when an incident is created.
Why this is correct
An automation rule can be set to trigger when a Sentinel incident is created, and its action can call a playbook. The playbook, a Logic App, can use the Exchange Online connector to block the sender, disable the account, or quarantine the email, depending on the response logic. Because automation rules fire immediately on incident creation, this option provides the desired automated response to the phishing event. This is the designated mechanism for incident-driven orchestration in Sentinel.
- ✗
Enable UEBA to detect anomalous email behavior.
Why it's wrong here
UEBA (User and Entity Behavior Analytics) in Sentinel learns baseline behavior and scores anomalies, but it is a detection and investigation tool, not a response engine. It does not contain actions to block an email sender or remediate a phishing incident. While UEBA insights can increase incident severity or be used by analytics rules, the feature itself does not execute automated response workflows. Thus, enabling UEBA alone will not satisfy the requirement to automatically respond to created incidents.
- ✗
Create an analytics rule that queries user-reported phishing data.
Why it's wrong here
Creating an analytics rule that queries user-reported phishing data will only generate new incidents from that telemetry, not act on an already-created incident. Analytics rules are scheduled queries that produce alerts and incidents; they do not execute response actions on existing incidents. After an incident exists, the only native way to launch automated actions is an automation rule (optionally invoking a playbook), not another analytics query. This approach conflates detection logic with the separate response orchestration layer.
Go deeper
Related to this question
About these practice questions
One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
2 more ways this is tested on SC-100
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Your organization uses Microsoft Sentinel and wants to automatically respond to high-severity incidents. Which feature should you configure?
easy- ✓ A.Configure an automation rule to run a playbook automatically
- B.Create a playbook and run it manually for each incident
- C.Set up an analytics rule with automatic response
- D.Use a workbook to trigger a playbook
Why A: Automation rules in Microsoft Sentinel allow you to define automated responses that trigger when an incident is created or updated, including running playbooks (Azure Logic Apps workflows) automatically. This is the correct approach for automatically responding to high-severity incidents because it eliminates manual intervention and ensures consistent, immediate action based on incident properties like severity.
Variation 2. Your organization uses Microsoft Sentinel and wants to automatically respond to high-severity incidents without human intervention. Which feature should you configure?
easy- ✓ A.Automation rule
- B.Analytics rule
- C.Workbook
- D.Watchlist
Why A: Automation rules in Microsoft Sentinel allow you to define automated responses to incidents based on conditions such as severity, without requiring human intervention. When a high-severity incident is created or updated, an automation rule can trigger a playbook (via Azure Logic Apps) to perform actions like blocking an IP, resetting a user password, or creating a support ticket, enabling fully automated incident response.
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.