Courseiva

SC-200 Manage a security operations environment Practice Question

Exhibit

Refer to the exhibit.
```json
{
  "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
  "contentVersion": "1.0.0.0",
  "resources": [
    {
      "type": "Microsoft.OperationalInsights/workspaces/savedSearches",
      "apiVersion": "2020-08-01",
      "name": "[concat(parameters('workspaceName'), '/', parameters('ruleName'))]",
      "properties": {
        "category": "Security",
        "displayName": "[parameters('ruleName')]",
        "query": "SecurityEvent | where EventID == 4688 | where ProcessName endswith '\\powershell.exe'",
        "tags": [
          { "name": "AlertSeverity", "value": "Medium" }
        ]
      }
    }
  ]
}
```

Refer to the exhibit. You are deploying an Azure Resource Manager (ARM) template to create a saved search in Microsoft Sentinel. However, the template does not create an analytics rule. What is missing to turn this saved search into a scheduled analytics rule?

⚠ Common exam trap

A common mix-up: candidates assume a saved search with a KQL query automatically becomes a scheduled analytics rule, when in fact a separate schedule resource is required to define the run frequency and time window.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A Microsoft.OperationalInsights/workspaces/savedSearches/schedules resource

In Microsoft Sentinel, a saved search alone is just a stored KQL query; to turn it into a scheduled analytics rule that runs periodically and generates alerts, you must define a schedule resource under the saved search. The correct resource type is `Microsoft.OperationalInsights/workspaces/savedSearches/schedules`, which specifies the frequency and time period for the query execution. Without this schedule resource, the saved search remains static and never triggers alerts.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A Schedule section with frequency and period

    Why it's wrong here

    A standalone Schedule section with frequency and period is not a deployable resource type. In an Azure Resource Manager template, schedule settings are strictly a property nested inside a valid alert rule resource such as Microsoft.Insights/scheduledQueryRules or Microsoft.OperationalInsights/workspaces/savedSearches/schedules. Without that parent resource, the ARM deployment has no resource type to validate or create, so the schedule values are meaningless and the template will fail. You cannot deploy a frequency and period by themselves; they must be attached to a resource that understands them.

  • ✗

    An IncidentConfiguration section

    Why it's wrong here

    IncidentConfiguration is a nested property of a Microsoft.Insights/scheduledQueryRules resource, not a standalone deployable unit. It controls whether Microsoft Sentinel creates incidents from the alerts generated by that specific scheduled query rule. Because the exhibited template lacks the parent alert rule resource entirely, adding an IncidentConfiguration section leaves the deployment engine with no resource to host it. In short, you are configuring incident behavior for a rule that does not exist in the template, so the deployment will not succeed.

  • ✓

    A Microsoft.OperationalInsights/workspaces/savedSearches/schedules resource

    Why this is correct

    The Microsoft.OperationalInsights/workspaces/savedSearches/schedules resource is the missing deployable component in the classic Log Analytics alert model. A saved search alone only stores a query; it does nothing until a schedule child resource is attached to it to run the query repeatedly, define the frequency and time window, and send notifications when results match. This resource type is recognized by ARM as a child of the savedSearch resource and is required to create a classic scheduled alert. The correct answer is to add this schedule resource to the template, even though modern deployments commonly use Microsoft.Insights/scheduledQueryRules instead.

  • ✗

    A Query property with a valid KQL

    Why it's wrong here

    The KQL query is already present in the exhibited template, so adding another Query property with a valid KQL expression is redundant and does not address the missing alert scheduling layer. A well-formed query can identify anomalous data, but it cannot trigger a notification unless a schedule resource or a scheduled query rule references it. In this template, the saved search already contains the correct query; what is absent is the recurrence mechanism that executes the query on a timer. Therefore, adding a query property does not provide the required resource and will leave the template invalid or incomplete.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.