Courseiva
easyMultiple Choice

SC-200 Practice Question: A SOC analyst is creating a new analytics rule in…

A SOC analyst is creating a new analytics rule in Microsoft Sentinel to detect when a user account is disabled. The analyst needs to select a rule template that uses Microsoft Entra ID audit logs. Which rule type should the analyst choose?

⚠ Common exam trap

A common trap is confusing NRT rules with scheduled rules. NRT rules do support AuditLogs, but they are limited to specific tables and are not the standard for template-based detections; scheduled rules are the default choice for built-in templates that query AuditLogs.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Scheduled

A scheduled query rule is the correct choice because it allows the analyst to define a KQL query that runs on a fixed interval against Microsoft Entra ID audit logs (AuditLogs table). This is the standard approach for built-in rule templates and provides full control over query logic and scheduling. While NRT rules also support AuditLogs, they are not used for standard rule templates and are more suited to custom high-frequency detections.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Scheduled

    Why this is correct

    Scheduled query rules are the standard analytics rule type that execute a custom KQL query at a defined frequency over a set lookback window, and they can query any table in the Log Analytics workspace, including AuditLogs for Microsoft Entra ID. This makes them fully appropriate for detecting a specific event such as 'user account disabled' because the query can filter on event name and other properties. They also support configurable alert grouping, entity mapping, and incident auto-creation, giving the SOC analyst complete control over detection logic.

  • ✗

    NRT (Near-Real-Time)

    Why it's wrong here

    Near-Real-Time (NRT) detection rules are intended for scenarios that require very low latency, but they are restricted to a specific list of supported tables and data sources that currently does not include the Microsoft Entra ID AuditLogs table. NRT rules also have inherent KQL limitations, such as disallowing certain operators and cross-table joins, which would limit the ability to write a robust query for an account disable event. While they offer fast speed, these constraints make them an incorrect choice for this scenario.

  • ✗

    Anomaly

    Why it's wrong here

    Anomaly rules in Microsoft Sentinel depend on built-in machine learning models to compare observed activity to a historical baseline and flag deviations. The event 'user account disabled' is a known, deterministic action rather than a statistically unusual pattern, so an anomaly model would not inherently trigger on that exact event. These rules are also not structured as customizable KQL queries and rely on predefined model inputs, making them unsuited for a straightforward event-detection requirement.

  • ✗

    Fusion

    Why it's wrong here

    Fusion rules are prebuilt correlation rules in Microsoft Sentinel that combine alerts from multiple security products to identify multi-stage attack chains (for example, signals from Microsoft Defender for Endpoint and Defender for Identity). A single event like a user account being disabled does not provide the multiple high-confidence signals required for a Fusion correlation, and Fusion logic is not customizable with arbitrary KQL queries against tables like AuditLogs. Therefore, this rule type is not suitable for the SOC analyst's simple event-detection use case.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.