Courseiva
mediumMatching

SC-200 Practice Question: Match each Microsoft Sentinel feature to its…

Match each Microsoft Sentinel feature to its purpose.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Define conditions that generate incidents

Visualize data using custom dashboards

Proactively search for threats

Automate responses using Azure Logic Apps

Detect anomalous behavior based on entity analytics

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Analytics rules: Automatically create security incidents based on data queries and alerts.

Analytics rules generate incidents, Workbooks visualize data, Hunting queries search for threats, and Playbooks automate response. Common confusions include mixing visualization with rule generation and automation with proactive search.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Analytics rules: Automatically create security incidents based on data queries and alerts.

    Why this is correct

    Analytics rules in Microsoft Sentinel are detection logic, typically KQL-based scheduled queries or Microsoft security rule templates, that run on a defined frequency. When the query returns results that meet a configured alert threshold, the rule automatically creates an incident with the relevant entities and alerts. They are the core automated detection layer that turns log data into triage-ready security incidents.

  • ✓

    Workbooks: Visualize data and create interactive reports with custom dashboards.

    Why this is correct

    Workbooks are interactive reporting canvases built on Azure Monitor Workbooks that let analysts visualize Sentinel security data with charts, grids, and tiles. They support custom parameters, multiple queries, and drill-down capabilities, enabling tailored dashboards for metrics, threat trends, and SOC KPIs. Unlike analytics rules, they do not generate incidents; they are for human-driven visibility and reporting.

  • ✓

    Hunting queries: Proactively search for threats using KQL queries.

    Why this is correct

    Hunting queries are interactive KQL searches launched from the Microsoft Sentinel Hunting blade to proactively discover threats, indicators of compromise, or unusual activity that automated detections may miss. Analysts can pivot on entities, bookmark results, and add them to incidents, and can later convert a proven query into an analytics rule. They represent a proactive, hypothesis-driven investigation approach rather than passive alerting.

  • ✓

    Playbooks: Automate incident response actions using Azure Logic Apps.

    Why this is correct

    Playbooks are orchestrated workflows built on Azure Logic Apps that execute automated incident response actions when triggered by an alert, incident, or automation rule. They can call connectors to enforce isolation, block IPs, notify teams, or run approval sequences, translating SOC playbooks into executable steps. Their primary purpose is to automate and streamline the response after detection, not to perform detection itself.

  • ✗

    Analytics rules: Visualize security data on custom dashboards.

    Why it's wrong here

    This is incorrect because analytics rules are not visualization tools; they are backend query rules that evaluate data and generate alerts or incidents based on conditions. Rich, interactive dashboards for security data are the function of Workbooks, which render KQL query results as visualizations. While analytics rules can produce output that might be visualized later, they do not display dashboards themselves.

  • ✗

    Playbooks: Proactively search for unknown threats in logs.

    Why it's wrong here

    This is incorrect because playbooks are not query-based search mechanisms; they are automated response workflows that act on incidents or alerts, such as containing a compromised host or notifying an administrator. Proactively searching logs for unknown or suspicious threats is done through Hunting queries, which are interactive KQL searches initiated by an analyst. Playbooks execute after an incident is created, not before it is discovered.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.