SC-200 Manage a security operations environment Practice Question
Exhibit
Refer to the exhibit.
```json
{
"$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
"contentVersion": "1.0.0.0",
"resources": [
{
"type": "Microsoft.OperationalInsights/workspaces/savedSearches",
"apiVersion": "2020-08-01",
"name": "[concat(parameters('workspaceName'), '/', parameters('ruleName'))]",
"properties": {
"category": "Security",
"displayName": "[parameters('ruleName')]",
"query": "SecurityEvent | where EventID == 4688 | where ProcessName endswith '\\powershell.exe'",
"tags": [
{ "name": "AlertSeverity", "value": "Medium" }
]
}
}
]
}
```Refer to the exhibit. You are deploying an Azure Resource Manager (ARM) template to create a saved search in Microsoft Sentinel. However, the template does not create an analytics rule. What is missing to turn this saved search into a scheduled analytics rule?
⚠ Common exam trap
A common mix-up: candidates assume a saved search with a KQL query automatically becomes a scheduled analytics rule, when in fact a separate schedule resource is required to define the run frequency and time window.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A Microsoft.OperationalInsights/workspaces/savedSearches/schedules resource
In Microsoft Sentinel, a saved search alone is just a stored KQL query; to turn it into a scheduled analytics rule that runs periodically and generates alerts, you must define a schedule resource under the saved search. The correct resource type is `Microsoft.OperationalInsights/workspaces/savedSearches/schedules`, which specifies the frequency and time period for the query execution. Without this schedule resource, the saved search remains static and never triggers alerts.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A Schedule section with frequency and period
Why it's wrong here
A standalone Schedule section with frequency and period is not a deployable resource type. In an Azure Resource Manager template, schedule settings are strictly a property nested inside a valid alert rule resource such as Microsoft.Insights/scheduledQueryRules or Microsoft.OperationalInsights/workspaces/savedSearches/schedules. Without that parent resource, the ARM deployment has no resource type to validate or create, so the schedule values are meaningless and the template will fail. You cannot deploy a frequency and period by themselves; they must be attached to a resource that understands them.
- ✗
An IncidentConfiguration section
Why it's wrong here
IncidentConfiguration is a nested property of a Microsoft.Insights/scheduledQueryRules resource, not a standalone deployable unit. It controls whether Microsoft Sentinel creates incidents from the alerts generated by that specific scheduled query rule. Because the exhibited template lacks the parent alert rule resource entirely, adding an IncidentConfiguration section leaves the deployment engine with no resource to host it. In short, you are configuring incident behavior for a rule that does not exist in the template, so the deployment will not succeed.
- ✓
A Microsoft.OperationalInsights/workspaces/savedSearches/schedules resource
Why this is correct
The Microsoft.OperationalInsights/workspaces/savedSearches/schedules resource is the missing deployable component in the classic Log Analytics alert model. A saved search alone only stores a query; it does nothing until a schedule child resource is attached to it to run the query repeatedly, define the frequency and time window, and send notifications when results match. This resource type is recognized by ARM as a child of the savedSearch resource and is required to create a classic scheduled alert. The correct answer is to add this schedule resource to the template, even though modern deployments commonly use Microsoft.Insights/scheduledQueryRules instead.
- ✗
A Query property with a valid KQL
Why it's wrong here
The KQL query is already present in the exhibited template, so adding another Query property with a valid KQL expression is redundant and does not address the missing alert scheduling layer. A well-formed query can identify anomalous data, but it cannot trigger a notification unless a schedule resource or a scheduled query rule references it. In this template, the saved search already contains the correct query; what is absent is the recurrence mechanism that executes the query on a timer. Therefore, adding a query property does not provide the required resource and will leave the template invalid or incomplete.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.