Courseiva

SC-200 Manage a security operations environment Practice Question

Exhibit

Refer to the exhibit.
```json
{
  "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
  "contentVersion": "1.0.0.0",
  "resources": [
    {
      "type": "Microsoft.OperationalInsights/workspaces/savedSearches",
      "apiVersion": "2021-06-01",
      "name": "[concat(parameters('workspaceName'), '/MyRule')]",
      "properties": {
        "displayName": "My Rule",
        "category": "Security",
        "query": "SecurityEvent | where EventID == 4625",
        "tags": []
      }
    }
  ]
}
```

You are deploying an ARM template to create a saved search in a Log Analytics workspace. The template fails with an error that the resource type is not valid for Microsoft Sentinel. What is the most likely reason?

⚠ Common exam trap

Many candidates confuse Log Analytics saved searches with Microsoft Sentinel analytics rules, assuming both use the same resource type, when in fact Sentinel requires the Microsoft.SecurityInsights/alertRules type.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The resource type should be Microsoft.SecurityInsights/alertRules, not OperationalInsights/workspaces/savedSearches.

Microsoft Sentinel does not use the OperationalInsights/workspaces/savedSearches resource type for its analytics rules. Instead, Sentinel uses the Microsoft.SecurityInsights/alertRules resource type to define detection rules. The ARM template fails because the resource type specified is not recognized as valid for Sentinel deployments.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The query is invalid KQL.

    Why it's wrong here

    The KQL expression used in the template's query property is well-formed and executable within Log Analytics, so the deployment is not failing because of syntax. When the intended outcome is a Microsoft Sentinel scheduled alert, the query string itself can be valid KQL and still be ineffective because the resource type determines how the query is used. Invalid KQL would produce a different error, such as a schema-validation or API-returned parse failure, not the resource-provider mismatch described here.

  • ✗

    The apiVersion is incorrect.

    Why it's wrong here

    The apiVersion declared in the template is a legitimate, supported version for Microsoft.OperationalInsights/workspaces/savedSearches, so ARM will accept it against that resource type. Even if Microsoft.SecurityInsights/alertRules requires its own apiVersion such as 2022-11-01 or later, the template's current apiVersion is valid for the saved searches resource and is not the root cause of the intended analytics rule not being created. Changing apiVersion alone would not transform a saved search into an alert rule.

  • ✓

    The resource type should be Microsoft.SecurityInsights/alertRules, not OperationalInsights/workspaces/savedSearches.

    Why this is correct

    To create a Microsoft Sentinel analytics rule, the template must use Microsoft.SecurityInsights/alertRules as the resource type, because scheduled analytics rules are owned by the SecurityInsights resource provider, not by Log Analytics. A saved search only stores a reusable KQL query and returns results manually; it does not generate alerts or run on a schedule. Deploying Microsoft.OperationalInsights/workspaces/savedSearches therefore creates the query artifact but never satisfies the requirement to provision a Sentinel alert rule, making this the correct diagnosis.

  • ✗

    The name format is incorrect.

    Why it's wrong here

    For a nested ARM resource, the name property is expected to follow a parent/child pattern, for example '[concat(parameters('workspaceName'), '/', parameters('searchName'))]', and the template's name follows that standard convention. A malformed name would fail with an ARM resource name validation error or an invalid resource identifier, but this template already uses the correct nesting format and would be accepted by the deployed resource type. The actual defect is not how the resource is named but which resource provider and type is being declared.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.