Courseiva

SC-100 Practice Question: Design security operations, identity, and compliance capabilities

Your organization uses Microsoft Sentinel and wants to automatically respond to high-severity incidents without human intervention. Which feature should you configure?

⚠ Common exam trap

Test-takers frequently confuse the detection phase (analytics rules) with the response phase (automation rules), leading candidates to select analytics rules because they think 'automated response' is part of the detection logic, when in fact analytics rules only generate alerts, not automated actions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Automation rule

Automation rules in Microsoft Sentinel allow you to define automated responses to incidents based on conditions such as severity, without requiring human intervention. When a high-severity incident is created or updated, an automation rule can trigger a playbook (via Azure Logic Apps) to perform actions like blocking an IP, resetting a user password, or creating a support ticket, enabling fully automated incident response.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Automation rule

    Why this is correct

    An automation rule is the correct answer because it provides the incident-level response engine within Microsoft Sentinel. It evaluates configurable conditions (such as severity, tag, or entity properties) and then executes actions automatically—including triggering a playbook, changing incident status, assigning an owner, or adding tasks—without human intervention. Because it runs on every matching incident at creation or update, it directly implements the required automated response to Sentinel incidents.

  • ✗

    Analytics rule

    Why it's wrong here

    An analytics rule is fundamentally a detection construct: it runs KQL queries on a schedule or in near-real time and creates an alert or incident when the query returns results. Despite the name, it does not automate any post-detection action; its only output is a notification that something was found. To actually respond, analytics rules rely on separate automation rules or playbooks, so selecting an analytics rule would not satisfy the requirement for automated response.

  • ✗

    Workbook

    Why it's wrong here

    A workbook is an interactive reporting and visualization tool built on KQL queries and Azure Resource Manager templates. It aggregates and displays Sentinel data in dashboards, charts, and tables, but it is passive: it does not monitor for new incidents, evaluate conditions in real time, or trigger any workflow. Because workbooks only present data for human analysis, they cannot serve as an automated response mechanism.

  • ✗

    Watchlist

    Why it's wrong here

    A watchlist is a user-managed collection of high-value data (often from a CSV file) that is stored in Sentinel and used for enrichment, detection, and correlation. Queries in analytics rules and playbooks can reference watchlists via the `_GetWatchlist` function, but the watchlist itself is inert—it does not run code or watch for events. It is a static lookup table, not an orchestrator, so it cannot automate a response to incidents.

About these practice questions

One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.