Courseiva

SC-100 Practice Question: Design security operations, identity, and compliance capabilities

Your organization uses Microsoft Sentinel and Microsoft Defender for Cloud. You need to design a solution that automatically creates an incident in Sentinel when a high-severity alert is generated in Defender for Cloud. What should you configure?

⚠ Common exam trap

A common mix-up: candidates confuse a playbook (which automates responses) with the analytics rule that actually creates the incident, or they think a workbook or watchlist can trigger incident creation, but only an analytics rule with the proper data connector can automatically generate incidents from ingested alerts.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable the Microsoft Defender for Cloud data connector and create an analytics rule

The Microsoft Defender for Cloud data connector ingests security alerts from Defender for Cloud into Microsoft Sentinel. Once ingested, you create an analytics rule with a rule query that triggers on high-severity alerts and configures the rule to automatically create an incident. This is the standard method to convert a Defender for Cloud alert into a Sentinel incident without manual intervention.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Enable the Microsoft Defender for Cloud data connector and create an analytics rule

    Why this is correct

    The Defender for Cloud data connector ingests security alerts from connected workloads into the Microsoft Sentinel workspace as raw events. However, incidents are not created automatically from these alerts; you must configure an analytics rule (typically a Microsoft security rule of type 'Microsoft Defender for Cloud') to transform the relevant alerts into incidents with assigned severity, status, and ownership. This two-step flow is the only way to get the expected incident-creation behavior from Defender for Cloud alerts.

  • ✗

    Create a workbook to track alerts

    Why it's wrong here

    Workbooks are interactive dashboards built on top of KQL queries that visualize data already stored in Sentinel, such as alerts, incidents, and trends. They are purely read-only and cannot trigger any automated process, nor do they have a mechanism to create incidents. To create incidents from alerts, you need an analytics rule that defines a schedule and a query; a workbook simply presents the results of those queries after the fact.

  • ✗

    Create a playbook in Microsoft Sentinel

    Why it's wrong here

    Playbooks in Microsoft Sentinel are automated response workflows constructed in Azure Logic Apps. They are designed to react to an incident or an alert by executing actions such as containment, investigation, or notification, but they cannot be used as the initial trigger for incident generation. An incident must already exist before a playbook can run; incident creation is the job of an analytics rule, so relying on a playbook alone would leave alerts unmanaged.

  • ✗

    Use a watchlist to import alerts

    Why it's wrong here

    Watchlists are collections of reference data, such as trusted IP addresses or malicious domains, that you can store locally and use in analytics rules or queries for enrichment and correlation. Importing alerts into a watchlist would merely create a static snapshot of those alerts for lookup purposes; it does not feed the alerts into Sentinel's event pipeline nor does it generate incidents. Watchlists are not a data connector and have no built-in logic to evaluate alert severity or create incident records.

About these practice questions

Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.