Courseiva

SC-200 Manage a security operations environment Practice Question

Exhibit

Refer to the exhibit.

{
  "properties": {
    "displayName": "Sensitive Data Access",
    "description": "Detect access to sensitive data",
    "severity": "Medium",
    "query": "SensitivityLabelEvent | where SensitivityLabelName contains \"Confidential\" | where OperationName == \"FileAccessed\"",
    "queryFrequency": "PT1H",
    "queryPeriod": "PT1H",
    "triggerOperator": "GreaterThan",
    "triggerThreshold": 0,
    "suppressionDuration": "PT5H",
    "suppressionEnabled": false,
    "tactics": ["Collection"],
    "alertRuleTemplateName": null
  }
}

You are reviewing an analytics rule in Microsoft Sentinel. The rule is supposed to alert when a Confidential sensitivity label file is accessed. However, no alerts have been generated despite known accesses. What is the most likely reason?

⚠ Common exam trap

Microsoft often tests the misconception that a rule's logic or scheduling is the root cause, when in fact the underlying data source is missing or misconfigured — candidates overlook the prerequisite of having the correct data connector enabled.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The required data connector for Microsoft Purview Information Protection is not connected.

The query should reference the MicrosoftPurviewInformationProtection table (populated by the Microsoft Purview Information Protection data connector), not a nonexistent 'SensitivityLabelEvent' table. With the connector disconnected, that table is empty, which is why the rule's query returns zero rows and no alert fires despite the query logic, schedule, and trigger threshold all being otherwise correct.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The suppression duration is set to 5 hours, which suppresses alerts.

    Why it's wrong here

    The suppression duration is not the cause of the missed alerts because the suppression feature is explicitly disabled in this rule via the `suppressionEnabled: false` setting. With suppression disabled, the 5-hour value is inert, meaning every occurrence of the alert is generated independently. Even if suppression were enabled, it would only mute alerts after the first firing, not prevent the query from detecting events in the first place.

  • ✓

    The required data connector for Microsoft Purview Information Protection is not connected.

    Why this is correct

    The `SensitivityLabelEvent` table is populated only when the Microsoft Purview Information Protection data connector is connected to Microsoft Sentinel. Without that connector, the table remains empty in the Log Analytics workspace, so the query for this analytics rule returns zero rows even if label consumption events are happening across the organization. This is the root cause because the rule's logic and trigger are sound, but the underlying telemetry is never ingested—so the alert never fires.

  • ✗

    The query frequency and period are too short to capture the events.

    Why it's wrong here

    A 1-hour query frequency with a matching period is not too short for most monitoring scenarios, as it means Sentinel executes the rule every hour and looks back at the last hour of data. Any events that occur within that hourly window would be evaluated, provided the correct tables are populated. The problem is not the temporal granularity but rather the absence of source data; without the connector, the query has no records to evaluate regardless of the schedule.

  • ✗

    The trigger condition is set to 'GreaterThan' 0, which should fire on any event.

    Why it's wrong here

    The trigger condition set to 'GreaterThan 0' is actually correct and should cause the alert to fire whenever the query yields even a single result. This is the default and recommended threshold for alerting on any matching event, so it is not a factor in the failed detection. The rule only returns zero results because the `SensitivityLabelEvent` table is empty due to the missing connector, which means the trigger condition never gets satisfied.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.