Courseiva

SC-200 Manage a security operations environment Practice Question

Exhibit

Refer to the exhibit.
```powershell
Connect-AzAccount
$workspace = Get-AzOperationalInsightsWorkspace -ResourceGroupName "rg-sentinel" -Name "la-sentinel-prod"
Set-AzSentinelSetting -Workspace $workspace -SettingName "Anomalies" -Enabled $true
```

Refer to the exhibit. You are running a PowerShell script to enable the Anomalies setting in Microsoft Sentinel. After running the script, you check the Sentinel settings in the portal and see that Anomalies is still disabled. What is the most likely reason?

⚠ Common exam trap

Many exam-takers assume all Azure PowerShell cmdlets follow the 'Set-*' naming convention, but Microsoft Sentinel settings specifically use 'Update-*' in the Az.SecurityInsights module, leading to the mistaken belief that 'Set-AzSentinelSetting' is valid.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The cmdlet 'Set-AzSentinelSetting' does not exist in the Az module.

The cmdlet 'Set-AzSentinelSetting' does not exist in the official Az.SecurityInsights module. Microsoft Sentinel settings, including Anomalies, are managed via the REST API or the 'Update-AzSentinelSetting' cmdlet (part of the Az.SecurityInsights preview module). Running a non-existent cmdlet would produce an error, not apply any changes, leaving Anomalies disabled in the portal.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The cmdlet 'Set-AzSentinelSetting' does not exist in the Az module.

    Why this is correct

    The non-existence of 'Set-AzSentinelSetting' in the Az module directly explains why the Anomalies setting remains disabled. PowerShell scripts fail when attempting to invoke cmdlets that are not recognised or do not exist within the loaded modules. This scenario indicates the script encountered an execution error because the specified cmdlet for modifying Sentinel settings was not found, preventing the intended configuration change from being applied.

  • ✗

    The user does not have Contributor permissions on the workspace.

    Why it's wrong here

    Permissions are not the issue here. If the user lacked Contributor (or Sentinel Contributor) access, the failure would surface as a Microsoft Graph or Azure Resource Manager authorization error after the cmdlet is invoked, such as 'AuthorizationFailed' or a 403 status. Here, PowerShell reports that 'Set-AzSentinelSetting' is not recognized as a cmdlet, which is a command-resolution failure that occurs during parsing, before any RBAC checks are performed. Even a user with Owner permissions on the workspace would encounter exactly the same error because the cmdlet is absent from the loaded Az modules.

  • ✗

    The script requires the -PassThru parameter to apply changes.

    Why it's wrong here

    The -PassThru parameter is a common PowerShell switch that returns the output object of a cmdlet so it can be piped or stored; it never determines whether a configuration change is persisted. In this scenario, PowerShell cannot even bind parameters because 'Set-AzSentinelSetting' does not exist in any imported module, so the script terminates immediately with a CommandNotFoundException. The intended change to the Anomalies setting is never attempted, and adding -PassThru would not make the invalid cmdlet resolvable or modify the underlying behavior.

  • ✗

    The workspace was not retrieved correctly because the name is misspelled.

    Why it's wrong here

    A misspelled workspace name would manifest as a resource lookup failure, not a cmdlet resolution error. The script would first need to obtain the workspace, typically via Get-AzOperationalInsightsWorkspace or Get-AzSentinelSetting with a workspace context, and an incorrect name would cause a 'ResourceNotFound' exception or return $null. Here, the PowerShell error explicitly flags 'Set-AzSentinelSetting' as an unrecognized command, which is independent of the workspace name and occurs at script parse time. Therefore, even a perfectly spelled workspace name would still produce the same failure because the cmdlet itself is missing.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.