SC-100 Practice Question: Design solutions that align with security best practices and priorities
Your organization uses Microsoft Sentinel for security operations. The SOC team wants to automatically disable a compromised user account in Microsoft Entra ID when a high-severity alert is generated. Which automation method should you use?
⚠ Common exam trap
It's easy for candidates to confuse analytics rules (which detect and alert) with automation rules (which respond), leading them to select an analytics rule thinking it can directly perform remediation actions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
An automation rule with a playbook
Automation rules in Microsoft Sentinel can trigger a playbook (an Azure Logic Apps workflow) when a high-severity alert fires. The playbook can then execute an action to disable the user account in Microsoft Entra ID via the Microsoft Graph API. This is the correct method because it provides the necessary integration between Sentinel alerts and Entra ID identity remediation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
An automation rule with a playbook
Why this is correct
An automation rule with a playbook is the correct choice for automated remediation because automation rules can be configured to trigger a playbook when an incident is created or updated. The playbook, built on Azure Logic Apps, can then execute actions such as calling Microsoft Graph API to disable a compromised user account, making it the only option here that both detects and responds automatically.
- ✗
A workbook
Why it's wrong here
A workbook is an interactive visual report in Microsoft Sentinel that uses KQL to query Log Analytics workspaces and display trends, anomalies, or security metrics. It is purely read-only and designed for monitoring and analysis; it cannot trigger any automated response actions like disabling a user account, so it is not suitable for this requirement.
- ✗
A KQL query in a hunting rule
Why it's wrong here
A KQL query in a hunting rule is used for proactive threat hunting, where security analysts search for suspicious activity based on hypotheses. While it can reveal indicators of compromise, a hunting rule only surfaces results for manual investigation and does not have any built-in remediation capabilities, so it cannot automatically disable a user account.
- ✗
An analytics rule
Why it's wrong here
An analytics rule generates alerts or incidents when its configured KQL query detects suspicious behavior, such as a risky user sign-in. However, an analytics rule stops at alert creation; it does not perform remediation actions itself. It only works together with an automation rule to trigger a playbook, so by itself it cannot disable a user account.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.