Courseiva

SC-100 Design security solutions for infrastructure Practice Question

Your organization is using Microsoft Sentinel to collect security logs from multiple sources, including Azure Activity Logs, Office 365 Audit Logs, and on-premises Windows Event Logs. You need to ensure that security incidents are automatically created when a user from a specific IP address attempts to access a sensitive application. You have already configured the data connectors. What should you create?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create an analytics rule that triggers an incident when access from the IP is detected.

The correct option is C: Create an analytics rule that triggers an incident when access from the IP is detected. In Microsoft Sentinel, analytics rules are the built-in mechanism that evaluates ingested log data against detection logic and automatically generates incidents when conditions match, which is exactly what is required to flag access attempts from a specific IP to a sensitive application. A watchlist (option B) can store the IP for reference or enrichment in queries, but by itself it does not create incidents. A workbook (option A) is only a visualization/reporting tool and takes no automated action, and a playbook (option D) is an automation workflow that responds to incidents or alerts but does not itself detect the access or create the incident.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a workbook to visualize the access attempts.

    Why it's wrong here

    A workbook is a visualization layer in Microsoft Sentinel that plots KQL query results onto dashboards or interactive reports. It has no detection logic, does not run continuously, and cannot evaluate whether a specific IP address has accessed a resource. Even if the workbook clearly shows the suspicious IP, it is a passive, human-readable artifact—it cannot create an alert or incident on its own.

  • ✗

    Create a watchlist containing the IP address and use it in a query.

    Why it's wrong here

    A watchlist is a stored lookup table of data (such as the IP address) that you can join with event data in KQL queries for enrichment or correlation. It is a data source, not a detection mechanism, and simply creating a watchlist does not evaluate access attempts or generate incidents. To be useful for detection, the watchlist would first need to be referenced inside the query of an analytics rule—so it is a supporting component, not the solution.

  • ✓

    Create an analytics rule that triggers an incident when access from the IP is detected.

    Why this is correct

    An analytics rule in Microsoft Sentinel is the detection engine that runs a scheduled or near-real-time KQL query against the workspace. When the query returns results that match the rule's condition (for example, any logs showing access from the suspect IP), it triggers an alert and automatically creates an incident with associated entities, severity, and tactics. This is the only option that performs both detection and incident creation, making it the correct way to be alerted to such access.

  • ✗

    Create a playbook that runs when a specific event occurs.

    Why it's wrong here

    A playbook is a collection of actions built on Azure Logic Apps that automates a response after an alert or incident has already been generated. It must be triggered by an existing alert or incident—it cannot be triggered directly by a raw event or a query result. Therefore, while a playbook could run when a specific event occurs, it requires a preceding analytics rule to detect the event and create the incident; it cannot be the mechanism that creates the incident.

About these practice questions

This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.