mediumMultiple Select
SC-200 Practice Question: Detection scenarios can be implemented using a…
Which of the following detection scenarios can be implemented using a scheduled analytics rule in Microsoft Sentinel? (Select all that apply.) (Choose 2.)
⚠ Common exam trap
It's easy for candidates to confuse detection scenarios with response actions, or assume that all behavioral detection (like UEBA) can be done with scheduled rules, when in fact scheduled rules are only for static, query-based detection, not for machine learning or automated remediation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Identifying sign-ins from IP addresses listed in a custom threat intelligence watchlist.
Scheduled analytics rules in Microsoft Sentinel can be configured to run KQL queries at regular intervals. These queries can join multiple data sources, including watchlists and Windows Security Events (SecurityEvent table). For option A, querying SigninLogs and joining with a custom threat intelligence watchlist identifies sign-ins from malicious IPs. For option C, aggregating failed logon events from SecurityEvent (e.g., EventID 4625) and grouping by source IP or account can detect brute-force patterns. Option B is better suited for UEBA anomaly detection, and option D is an automated response action, not detection. Therefore, A and C are correct.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Identifying sign-ins from IP addresses listed in a custom threat intelligence watchlist.
Why this is correct
Scheduled analytics rules are the correct vehicle for matching sign-in events against a custom threat intelligence watchlist. In a scheduled rule’s KQL query, you can use the _GetWatchlist() function or a watchlist alias to join SigninLogs with known malicious IPs, generating alerts whenever a match occurs. This is a straightforward, deterministic indicator-based detection that fits scheduled-rule logic perfectly.
- ✗
Detecting anomalous sign-in behavior based on user entity behavior.
Why it's wrong here
UEBA-based anomaly detection in Microsoft Sentinel relies on built-in Anomaly analytics rules, not scheduled rules, because it requires machine learning models that analyze baseline and behavioral patterns for users and entities. A scheduled rule executes a KQL query on a fixed schedule and cannot perform the adaptive, context-aware scoring that UEBA uses to detect anomalous sign-ins. Therefore, attempting to configure entity behavior anomaly detection as a scheduled rule is incorrect.
- ✓
Correlating Windows Security Events to detect brute-force attacks.
Why this is correct
A scheduled analytics rule can absolutely correlate Windows Security Events such as Event ID 4625 (failed logon) across multiple hosts and time windows using KQL aggregations like summarize and count(). By grouping on TargetUserName, IpAddress, or WorkstationName, you can identify brute-force attack patterns when the number of failures exceeds a threshold. This is a valid scheduled-rule scenario because the detection logic is a deterministic query over log events.
- ✗
Automatically blocking malicious IPs on a firewall.
Why it's wrong here
Scheduled analytics rules are detection mechanisms that generate alerts and incidents; they do not directly execute response actions such as blocking an IP on a firewall. To automatically block a malicious IP, you need a playbook (Azure Logic Apps) that is triggered by an automation rule or by an incident creation, and that playbook then calls the firewall API. A scheduled rule has no native capability to enforce network hardening, making this option incorrect.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.