SC-200 Manage a security operations environment Practice Question
Exhibit
Refer to the exhibit.
```json
{
"$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
"contentVersion": "1.0.0.0",
"resources": [
{
"type": "Microsoft.OperationalInsights/workspaces/savedSearches",
"apiVersion": "2020-08-01",
"name": "[concat(parameters('workspaceName'), '/SampleSavedSearch')]",
"properties": {
"displayName": "Sample Saved Search",
"category": "Security",
"query": "SecurityEvent | where EventID == 4625 | where TimeGenerated > ago(1h)",
"tags": []
}
}
]
}
```You are reviewing the ARM template snippet shown in the exhibit. What is the purpose of this template?
⚠ Common exam trap
Candidates often confuse saved searches with other Log Analytics features like workbooks or analytics rules, but the resource type 'Microsoft.OperationalInsights/workspaces/savedSearches' is uniquely tied to saved queries, not visualizations or alerting logic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a saved search in a Log Analytics workspace
The ARM template snippet defines a saved search resource of type 'Microsoft.OperationalInsights/workspaces/savedSearches'. This resource type is specifically used to create a saved query within a Log Analytics workspace, which can then be used for log queries, alert rules, or workbooks. Option C correctly identifies this purpose.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a workbook in Azure Monitor
Why it's wrong here
The ARM template snippet specifies 'Microsoft.OperationalInsights/workspaces/savedSearches', which deploys a saved search inside an existing Log Analytics workspace. Azure Monitor workbooks are defined as 'Microsoft.Insights/workbooks' and are used for interactive dashboards and visualizations, not for storing query definitions. Therefore, this option incorrectly identifies the resource type in the template.
- ✗
Create an analytics rule in Microsoft Sentinel
Why it's wrong here
Creating an analytics rule in Microsoft Sentinel would require a resource of type 'Microsoft.SecurityInsights/alertRules' (or 'Microsoft.SecurityInsights/alertRules/scheduled') with properties such as queryFrequency, queryPeriod, and triggerOperator. The snippet's resource type is 'savedSearches', which is a Log Analytics workspace resource, not a Sentinel analytics rule. Analytics rules actively run queries to generate incidents, whereas a saved search merely stores a query in the workspace.
- ✓
Create a saved search in a Log Analytics workspace
Why this is correct
The resource type 'Microsoft.OperationalInsights/workspaces/savedSearches' is specifically used to create a saved search in a Log Analytics workspace. The 'properties' object includes 'category' and 'query', where the query is the KQL statement to be saved. This saved search can be reused in workbooks or pinned to dashboards, and it is the correct interpretation of this ARM template snippet.
- ✗
Create a data connector in Microsoft Sentinel
Why it's wrong here
A data connector in Microsoft Sentinel is deployed using resource types like 'Microsoft.SecurityInsights/dataConnectors' and configures ingestion from sources such as Microsoft Entra ID, Office 365, or AWS CloudTrail. The snippet represents 'Microsoft.OperationalInsights/workspaces/savedSearches', which does not enable any data ingestion or connectivity. Saved searches only store KQL queries within a Log Analytics workspace, so this option misidentifies the purpose of the resource in the template.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.