Courseiva

SC-200 Respond to security incidents Practice Question

Exhibit

Refer to the exhibit.

```json
{
  "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
  "contentVersion": "1.0.0.0",
  "resources": [
    {
      "type": "Microsoft.OperationalInsights/workspaces/savedSearches",
      "apiVersion": "2020-08-01",
      "name": "[concat(parameters('workspaceName'), '/', 'SuspiciousLogins')]",
      "properties": {
        "displayName": "Suspicious Logins",
        "category": "Security",
        "query": "SigninLogs | where RiskLevelDuringSignIn == 'medium' or RiskLevelAggregated  == 'medium' | where TimeGenerated > ago(1h)",
        "tags": [
          {"name": "Suspicious", "value": "High"}
        ]
      }
    }
  ]
}
```

You deploy this ARM template to a Microsoft Sentinel workspace. After deployment, you notice that the saved search does not appear as an analytics rule. What is the most likely reason?

⚠ Common exam trap

SC-200 often tests the distinction between saved searches and analytics rules in ARM templates, trapping candidates who assume any query resource will automatically become an analytics rule.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The resource type is 'savedSearches', not 'scheduledQueryRules' or 'alertRules'.

In Azure Resource Manager, the resource type determines what kind of object is created. A 'savedSearches' resource creates a saved search query in Log Analytics/Sentinel, which is a reusable query definition — not an analytics rule. Analytics rules in Microsoft Sentinel are created using the 'scheduledQueryRules' resource type (or the older 'alertRules' type). Therefore, even though the template deployed successfully, the saved search will never appear as an analytics rule because it is a fundamentally different resource type.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The tags are incorrectly formatted.

    Why it's wrong here

    Tags in an ARM template are defined as a top-level property of the resource object and must be a JSON object of key-value string pairs. In this template, the tags are formatted correctly, so they are not the cause of the failure. Even if a tag value were malformed, Azure Resource Manager would reject the template during validation before any resource is created, not silently deploy a different resource. The real problem is the resource type, not the optional tags.

  • ✓

    The resource type is 'savedSearches', not 'scheduledQueryRules' or 'alertRules'.

    Why this is correct

    A Microsoft Sentinel analytics rule must be deployed using either 'Microsoft.OperationalInsights/workspaces/scheduledQueryRules' (for scheduled rules) or 'Microsoft.SecurityInsights/alertRules' (the Sentinel-native provider). The template declares 'Microsoft.OperationalInsights/workspaces/savedSearches', which only stores a KQL query in the Log Analytics workspace and does not trigger any alert or incident logic. Because the resource type is wrong, nothing appears under the Analytics Rules blade in Sentinel; this is the root cause of the deployment's apparent failure.

  • ✗

    The API version is incorrect.

    Why it's wrong here

    The API version in the template, such as '2020-08-01' for the savedSearches resource type, is valid and supported for that specific resource type. API versions are scoped to a resource provider and type, so a version that works for savedSearches has no bearing on scheduledQueryRules or alertRules. The version is not the issue; the template deploys a different kind of resource than intended, and the API version simply matches that wrong resource type.

  • ✗

    The KQL query syntax is invalid.

    Why it's wrong here

    The KQL query string in a saved search resource is not interpreted or syntax-checked during ARM template deployment; it is stored as an opaque JSON string in the 'properties.query' field. The example query, such as one against 'SecurityEvent' with a filter, is syntactically valid and would run in Log Analytics. Because ARM never validates the query, invalid KQL cannot explain why the deployment failed to create an analytics rule—the query would only fail at runtime, not at deployment time.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.