Courseiva

SC-200 Manage a security operations environment Practice Question

Exhibit

{
  "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
  "contentVersion": "1.0.0.0",
  "parameters": {
    "workspaceName": {
      "type": "string"
    }
  },
  "resources": [
    {
      "type": "Microsoft.OperationalInsights/workspaces/savedSearches",
      "name": "[concat(parameters('workspaceName'), '/TestSearch')]",
      "apiVersion": "2020-08-01",
      "properties": {
        "displayName": "Test Search",
        "category": "Test",
        "query": "Heartbeat | summarize Count() by Computer",
        "tags": []
      }
    }
  ]
}

Refer to the exhibit. You deploy this ARM template to your subscription. After deployment, you cannot find the saved search 'Test Search' in the Microsoft Sentinel workspace. What is the most likely reason?

⚠ Common exam trap

Test-takers frequently assume any KQL query deployed via ARM template in a Log Analytics workspace will automatically appear as a Sentinel analytics rule, but Microsoft requires the correct resource provider and type for Sentinel-specific features.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The resource type should be for analytics rules, not saved searches.

The ARM template deploys a resource of type 'Microsoft.OperationsManagement/solutions' with a saved search, but Microsoft Sentinel does not use saved searches for analytics rules. In Sentinel, detection rules are created as 'Microsoft.SecurityInsights/alertRules', not as saved searches under a Log Analytics workspace. The template's resource type is mismatched for the intended functionality, so the saved search 'Test Search' will not appear as a Sentinel analytics rule.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The resource type should be for analytics rules, not saved searches.

    Why this is correct

    The core issue in this template is the resource type. Microsoft Sentinel analytics rules must be declared as `Microsoft.SecurityInsights/alertRules` (or under a Sentinel-compatible solution), not as `Microsoft.OperationalInsights/workspaces/savedSearches`. A savedSearches resource only creates a Log Analytics saved query, which will not appear in the Sentinel Analytics blade or generate alerts. Therefore, the deployment succeeds but the intended detection rule does not function.

  • ✗

    The query 'Heartbeat | summarize Count() by Computer' is invalid.

    Why it's wrong here

    The KQL expression `Heartbeat | summarize Count() by Computer` is syntactically valid: it groups heartbeat records by Computer and returns one row per computer with an aggregate column (often named `Count_`). The `summarize` operator accepts aggregate functions such as `count()` or its case-insensitive alias `Count()`, and omitting an explicit alias does not invalidate the query. Although the query may lack a meaningful column name, it parses and runs successfully in Log Analytics, so this is not the reason the ARM template fails.

  • ✗

    The apiVersion is incorrect.

    Why it's wrong here

    The `apiVersion` specified in the template is not incorrect. For the `Microsoft.OperationalInsights/workspaces/savedSearches` resource type, `2020-08-01` is a valid and widely supported API version that Microsoft continues to accept. This same apiVersion is also commonly used for `Microsoft.SecurityInsights/alertRules` in recent templates. An incorrect apiVersion would trigger a template validation error, but here it is acceptable, so this explanation is not the cause of the problem.

  • ✗

    The name concatenation is missing a parameter.

    Why it's wrong here

    The name concatenation in the template is complete and correct. A typical `savedSearches` resource name uses an expression like `[concat(parameters('workspaceName'), '/', parameters('savedSearchId'))]` for the `Microsoft.OperationalInsights/workspaces/savedSearches` type, and all required parameters are present. Missing a parameter would produce a template validation failure or a malformed resource name, but the name builds properly, so this explanation is false. The real problem is the resource type, which prevents the rule from being created as an analytics rule.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.