Courseiva

SC-100 Practice Question: Design security solutions for applications and data

Your organization uses Microsoft Sentinel for security information and event management (SIEM). You need to create an analytics rule that detects when a user account is created outside of business hours from an unusual IP address. Which type of rule should you use?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Scheduled query rule

The correct option is B, a Scheduled query rule, because this rule type lets you write a KQL query against your log data (e.g., SecurityEvent or AuditLogs) and schedule it to run at defined intervals, which is exactly what's needed to detect user account creation events filtered by time-of-day and unusual source IP conditions. Scheduled query rules support custom detection logic, entity mapping, and alert/incident generation, making them ideal for this scenario. Anomaly rules (A) are built-in templates that detect deviations from learned baselines and don't let you author arbitrary detection logic for specific conditions like account creation outside business hours. ML Behavior Analytics rules (C) are also prebuilt Microsoft-defined detections for specific behaviors, not customizable queries. Fusion rules (D) correlate multiple signals across products to detect multi-stage attacks and are not designed for a single custom condition like this.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Anomaly rule

    Why it's wrong here

    Anomaly rules in Microsoft Sentinel use built-in machine learning models to identify unusual behavior without requiring custom KQL definitions. They are not suitable for matching a specific, known pattern such as a user exceeding 10 failed sign-ins, because that is a deterministic condition, not a baseline deviation. The rule's logic is based on statistical deviations from a normal baseline, so it cannot enforce an exact numeric threshold.

  • ✓

    Scheduled query rule

    Why this is correct

    Scheduled query rules in Microsoft Sentinel let you author a KQL query that runs at a defined interval (for example, every 5 minutes) and can alert when the result set meets a specified condition. With KQL you can filter sign-in activity, aggregate by user, and compare the count of failed attempts to your threshold, giving you full control over the detection logic. This is the only rule type among the options that supports arbitrary custom KQL and deterministic alerting for a specific pattern.

  • ✗

    ML Behavior Analytics rule

    Why it's wrong here

    ML Behavior Analytics (MLBA) rules use machine learning models to analyze patterns of entity behavior, and they do not accept custom KQL queries or user-set numeric thresholds. They are built to detect deviations in a user's activities (such as impossible travel or unusual sign-in locations) rather than a fixed condition like 'more than 10 failed sign-ins in 5 minutes.' Since the scenario requires a precise KQL query and threshold, MLBA is the wrong choice.

  • ✗

    Fusion rule

    Why it's wrong here

    Fusion rules in Microsoft Sentinel correlate multiple alerts and signals to recognize multistage attack chains, using built-in logic and machine learning to combine evidence across different entities and time windows. They are not designed to run a user-defined query or to trigger on a simple threshold; instead, they automatically create incidents when a correlated attack sequence is detected. A single condition such as 'X failed sign-ins by one user' is not a multistage pattern, so Fusion does not apply here.

About these practice questions

Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.