SC-100 Playbook Practice Question
Your organization uses Microsoft Sentinel. You need to design a solution that automatically responds to a detected ransomware incident by isolating the affected device in Microsoft Defender for Endpoint. Which tool should you use to create the automated response?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a playbook in Microsoft Sentinel using Azure Logic Apps.
The correct option is B: create a playbook in Microsoft Sentinel using Azure Logic Apps. Playbooks are built on Azure Logic Apps and are the mechanism in Microsoft Sentinel for orchestrating automated response actions, including calling the Microsoft Defender for Endpoint connector to run the 'Isolate machine' action against an affected device. Automation rules (option C) can trigger playbooks and perform basic triage, but they do not themselves contain the multi-step response logic that isolates a device. A workbook (option A) is only a visualization/reporting tool, and a hunting query (option D) is a proactive search for threats, neither of which performs automated remediation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a workbook in Microsoft Sentinel.
Why it's wrong here
Workbooks in Microsoft Sentinel are Azure Monitor-based interactive dashboards designed for data visualization and reporting. They aggregate query results into charts and tables but are purely read-only, lacking any execution engine to initiate actions such as device isolation. To execute an automated response, a playbook is required, not a workbook.
- ✓
Create a playbook in Microsoft Sentinel using Azure Logic Apps.
Why this is correct
A playbook in Microsoft Sentinel is a collection of automated procedures built on Azure Logic Apps, enabling incident response actions such as isolating a device, disabling a user, or blocking an IP address. These playbooks contain the logic and steps that execute directly against security controls, and they can be triggered by alerts or incidents. This is exactly what is needed to design an automated response workflow.
- ✗
Create an automation rule in Microsoft Sentinel.
Why it's wrong here
Automation rules in Microsoft Sentinel are lightweight, rule-based triggers that manage incident lifecycle tasks like changing status, assigning ownership, or adding tags. They can invoke a playbook, but the rule itself only defines the trigger condition and the playbook reference—it does not contain the response logic. To isolate a device, the logic must reside inside a playbook, not in the automation rule.
- ✗
Create a hunting query in Microsoft Sentinel.
Why it's wrong here
Hunting queries are KQL (Kusto Query Language) queries used for proactive threat hunting and investigation, allowing analysts to search for indicators of compromise across workspace data. They are designed to identify potential threats, not to execute automated actions or respond to incidents. A hunting query would only surface suspicious activity; it cannot perform isolation or remediation.
Go deeper
Related to this question
About these practice questions
One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.