SC-200 Respond to security incidents Practice Question
Exhibit
Refer to the exhibit.
```json
{
"$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
"contentVersion": "1.0.0.0",
"resources": [
{
"type": "Microsoft.OperationalInsights/workspaces/savedSearches",
"apiVersion": "2020-08-01",
"name": "[concat(parameters('workspaceName'), '/', 'SuspiciousLogins')]",
"properties": {
"displayName": "Suspicious Logins",
"category": "Security",
"query": "SigninLogs | where RiskLevelDuringSignIn == 'medium' or RiskLevelAggregated == 'medium' | where TimeGenerated > ago(1h)",
"tags": [
{"name": "Suspicious", "value": "High"}
]
}
}
]
}
```You deploy this ARM template to a Microsoft Sentinel workspace. After deployment, you notice that the saved search does not appear as an analytics rule. What is the most likely reason?
⚠ Common exam trap
SC-200 often tests the distinction between saved searches and analytics rules in ARM templates, trapping candidates who assume any query resource will automatically become an analytics rule.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The resource type is 'savedSearches', not 'scheduledQueryRules' or 'alertRules'.
In Azure Resource Manager, the resource type determines what kind of object is created. A 'savedSearches' resource creates a saved search query in Log Analytics/Sentinel, which is a reusable query definition — not an analytics rule. Analytics rules in Microsoft Sentinel are created using the 'scheduledQueryRules' resource type (or the older 'alertRules' type). Therefore, even though the template deployed successfully, the saved search will never appear as an analytics rule because it is a fundamentally different resource type.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The tags are incorrectly formatted.
Why it's wrong here
Tags in an ARM template are defined as a top-level property of the resource object and must be a JSON object of key-value string pairs. In this template, the tags are formatted correctly, so they are not the cause of the failure. Even if a tag value were malformed, Azure Resource Manager would reject the template during validation before any resource is created, not silently deploy a different resource. The real problem is the resource type, not the optional tags.
- ✓
The resource type is 'savedSearches', not 'scheduledQueryRules' or 'alertRules'.
Why this is correct
A Microsoft Sentinel analytics rule must be deployed using either 'Microsoft.OperationalInsights/workspaces/scheduledQueryRules' (for scheduled rules) or 'Microsoft.SecurityInsights/alertRules' (the Sentinel-native provider). The template declares 'Microsoft.OperationalInsights/workspaces/savedSearches', which only stores a KQL query in the Log Analytics workspace and does not trigger any alert or incident logic. Because the resource type is wrong, nothing appears under the Analytics Rules blade in Sentinel; this is the root cause of the deployment's apparent failure.
- ✗
The API version is incorrect.
Why it's wrong here
The API version in the template, such as '2020-08-01' for the savedSearches resource type, is valid and supported for that specific resource type. API versions are scoped to a resource provider and type, so a version that works for savedSearches has no bearing on scheduledQueryRules or alertRules. The version is not the issue; the template deploys a different kind of resource than intended, and the API version simply matches that wrong resource type.
- ✗
The KQL query syntax is invalid.
Why it's wrong here
The KQL query string in a saved search resource is not interpreted or syntax-checked during ARM template deployment; it is stored as an opaque JSON string in the 'properties.query' field. The example query, such as one against 'SecurityEvent' with a filter, is syntactically valid and would run in Log Analytics. Because ARM never validates the query, invalid KQL cannot explain why the deployment failed to create an analytics rule—the query would only fail at runtime, not at deployment time.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.