SC-100 Practice Question: Design security solutions for applications and data
Your organization uses Microsoft Sentinel to detect threats. You need to design a solution that automatically remediates a detected threat on an Azure VM by isolating the VM from the network. What should you use?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a Microsoft Sentinel automation rule that triggers a playbook to run an Azure Automation runbook to modify the NSG.
Microsoft Sentinel can trigger a playbook (automation rule) that runs an Azure Automation runbook to modify the NSG and isolate the VM. Option B is wrong because Log Analytics workspace doesn't have remediation actions. Option C is wrong because Azure Policy is for compliance, not incident response. Option D is wrong because Defender for Cloud has some automation, but Sentinel playbook is the designed method for automated response.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create a Microsoft Sentinel automation rule that triggers a playbook to run an Azure Automation runbook to modify the NSG.
Why this is correct
Microsoft Sentinel automation rules are designed to invoke playbooks (Logic Apps) in response to security alerts. A playbook can call an Azure Automation runbook, which can programmatically update the NSG to add a deny rule for the compromised VM, quarantining it from network traffic. This is the correct SOAR-based remediation approach because it leverages Sentinel's native alert triggers and Azure Automation's compute capabilities.
- ✗
Configure a Log Analytics workspace query to run on a schedule and automatically block the VM.
Why it's wrong here
A Log Analytics workspace scheduled query (e.g., an alert rule using KQL) is a read-only detection mechanism; it can query security event data but cannot directly execute remediation like blocking a VM. While a scheduled alert can trigger an action group, that action group would still need a runbook or webhook to modify the NSG—the query itself has no ability to mutate Azure resources. Therefore, this option incorrectly implies the query performs the blocking action independently.
- ✗
Use Azure Policy to audit and automatically remediate non-compliant VMs.
Why it's wrong here
Azure Policy is a governance and compliance service that evaluates resource configurations against policy definitions and can remediate drift (e.g., deploy necessary extensions, alter tags), but it is not an incident response tool. It cannot react to a dynamic Sentinel alert about a compromised VM in real time; policies apply continuously to resource states and are not designed to quarantine a VM after a security detection. Thus it fails to address the immediate threat isolation requirement.
- ✗
Enable Microsoft Defender for Cloud's 'Just-in-time VM access' policy.
Why it's wrong here
Microsoft Defender for Cloud's Just-in-time (JIT) VM access is a proactive security control that locks down inbound traffic to management ports and grants temporary access when approved. It only reduces the attack surface but provides no mechanism to automatically isolate or block a VM once it is already detected as compromised by Sentinel. The feature is about granting user access, not about quarantining a host after a breach, so it cannot fulfill the isolation requirement.
Go deeper
Related to this question
About these practice questions
This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.