SC-100 Design security solutions for infrastructure Practice Question
Your organization uses Microsoft Sentinel for security information and event management (SIEM). You need to design a solution to detect brute-force attacks against Azure virtual machines. The solution should use Azure Activity Logs and Windows Security Events. What should you configure in Sentinel?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a scheduled analytics rule
Sentinel can ingest Azure Activity Logs and Windows Events, and then use analytics rules to detect brute-force patterns. Option A is wrong because watchlists are for reference data, not detection logic. Option B is wrong because workbooks visualize data, not detect. Option D is wrong because playbooks automate responses, not detect.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a threat intelligence watchlist
Why it's wrong here
A watchlist in Microsoft Sentinel is a repository of user-specified reference data (e.g., IP addresses, hostnames, or file hashes) that is stored as a CSV or tabular file. You can join a watchlist to KQL queries to enrich or filter query results, but a watchlist itself has no scheduling engine, no query execution loop, and no alert generation capability—so it cannot proactively detect threats on its own. In short, watchlists are static data assets, not detection logic.
- ✗
Create a workbook
Why it's wrong here
A workbook in Microsoft Sentinel is an interactive, customizable dashboard built on Azure Workbooks. It runs KQL queries only when a user opens or refreshes the workbook to visualize data, and it has no background schedule or built-in alerting mechanism. Workbooks are designed for human analysis, reporting, and trend discovery—not for continuously monitoring incoming data and firing security alerts when suspicious activity is found.
- ✓
Create a scheduled analytics rule
Why this is correct
A scheduled analytics rule is the core detection primitive in Microsoft Sentinel. It defines a KQL query, a query frequency (how often to run), a lookback period (how much historical data to examine), and an alert threshold or result condition. When the query returns results on the schedule, the rule creates a security alert, optionally with entity mapping for investigation and automated responses. This is precisely the mechanism Sentinel uses for always-on, time-based threat detection across your workspace.
- ✗
Create a playbook
Why it's wrong here
A playbook in Sentinel is an automation workflow, typically built on Azure Logic Apps, that defines a set of actions to run when an alert or incident is triggered. Playbooks do not execute scheduled queries against your data workspace; instead, they consume already-generated alerts to perform response steps such as blocking an IP, resetting a credential, or posting to a channel. Creating a playbook addresses the 'respond' stage, not the 'detect' stage, so it is not a substitute for an analytics rule.
Go deeper
Related to this question
About these practice questions
One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.