SC-200 Respond to security incidents Practice Question
You have been tasked with creating an automated response in Microsoft Sentinel for incidents involving lateral movement. Which Azure service allows you to run a playbook to automatically isolate a compromised VM?
⚠ Common exam trap
It's easy for candidates to confuse 'automated response' with 'querying or hunting tools' (like KQL or advanced hunting) and overlook that only Logic Apps provides the actual workflow execution engine for playbooks in Sentinel.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Azure Logic Apps
Azure Logic Apps is the correct answer because it provides the workflow automation engine that powers Microsoft Sentinel playbooks. When a lateral movement incident is detected, a Logic Apps-based playbook can execute automated actions such as isolating a compromised VM via Azure Network Security Groups (NSGs) or Azure Firewall rules, using connectors like the Azure VM or Azure Resource Manager. This enables a no-code or low-code response directly from Sentinel without manual intervention.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Azure Logic Apps
Why this is correct
Playbooks in Microsoft Sentinel are built on Azure Logic Apps, which provide a visual designer to automate incident response actions such as blocking IPs, resetting passwords, or opening tickets. Logic Apps connectors integrate with many services, allowing you to orchestrate a wide range of response workflows. Therefore, Azure Logic Apps is the correct choice for creating an automated response in Sentinel.
- ✗
Kusto Query Language (KQL)
Why it's wrong here
Kusto Query Language (KQL) is a read-only query language used to search and analyze data across Azure Sentinel and other Azure Data Explorer services. While KQL is essential for hunting and investigation, it cannot execute any automated actions, trigger workflows, or call connectors. Its sole purpose is to return query results for analysis, so it is not a suitable platform for automated response.
- ✗
Microsoft Defender XDR advanced hunting
Why it's wrong here
Microsoft Defender XDR advanced hunting is a query-based threat-hunting capability that allows analysts to run KQL queries over raw signals from the Microsoft 365 ecosystem. Its purpose is to proactively identify and investigate threats, not to automate remediation or incident response actions. Advanced hunting lacks the workflow engine and integration connectors needed to execute playbook actions, making it incorrect for this task.
- ✗
Azure Event Hubs
Why it's wrong here
Azure Event Hubs is a big data streaming platform and event ingestion service that receives and processes millions of events per second, often used to feed security data into Sentinel. However, it does not contain a workflow engine or any orchestration capabilities to trigger response actions such as blocking a user or isolating a device. Its function is confined to data ingestion and telemetry transport, so it cannot create automated responses.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.