Courseiva

SC-200 Activity Logs Practice Question

Your organization is implementing Microsoft Sentinel and needs to ensure that incident response activities are compliant with regulatory requirements. You need to track and document all changes made to analytics rules and playbooks. Which TWO features should you enable?

⚠ Common exam trap

Candidates often confuse automation rules or workbooks as change-tracking tools. Remember that only Azure-native logging services (Activity Logs and Change History) provide the audit trail required for regulatory compliance.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Activity logs (Azure Monitor)

Activity logs (Azure Monitor) record all management-plane operations, including changes to analytics rules and playbooks, while Azure Resource Change History (Change tracking) captures resource-level modifications. Together they provide comprehensive audit trails for regulatory compliance. Workbooks (A) are for visualization, Automation rules (B) trigger responses but don't log changes themselves, and Microsoft Purview (E) is for broader data governance, not operational change tracking.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Sentinel workbooks

    Why it's wrong here

    Sentinel workbooks are interactive dashboards built on KQL queries against Log Analytics workspaces, used to visualize trends and outliers in your security data. While a workbook could be constructed to show changes if the data were already logged elsewhere, it is not a source of truth for change tracking. It neither records backend operations nor maintains a history of rule or playbook modifications, so it cannot provide the required audit evidence.

  • ✗

    Automation rules

    Why it's wrong here

    Automation rules automate responses to Sentinel incidents, such as assigning ownership, updating status, or invoking playbooks. However, they have no built-in logging mechanism for their own configuration changes; any alteration to an automation rule itself appears in the Azure Activity log as a resource write operation. Because they are the object of orchestration rather than an auditing service, they do not satisfy the compliance audit trail requirement.

  • ✓

    Activity logs (Azure Monitor)

    Why this is correct

    The Azure Activity log is the subscription-level platform log that records administrative operations on Azure resources, including every write (PUT, POST, PATCH) against Sentinel analytics rules, playbooks, and data connectors. Each entry captures the resource ID, the operation name, the initiating principal, and a timestamp, giving you a comprehensive compliance audit trail. To meet compliance requirements, you would enable diagnostic settings to export this log to a Log Analytics workspace for long-term retention and alerting.

  • ✓

    Azure Resource Change History (Change tracking)

    Why this is correct

    Azure Resource Change History, surfaced through the Change History tab in Azure Resource Graph, captures the before-and-after property values of Azure resource modifications. For Sentinel resources, it lets you drill into a specific analytics rule and see exactly which fields were changed, by whom, and when, complementing the Activity log's operational view. This granular property-level detail is particularly valuable for forensics and enforcement of change management policies.

  • ✗

    Microsoft Purview Compliance Manager

    Why it's wrong here

    Microsoft Purview Compliance Manager is a governance tool that generates regulatory compliance scores and provides controls for data protection standards, not an operational audit log. It assesses your posture against frameworks like CIS or NIST but does not capture administrative events occurring within Sentinel. Tracking who modified an analytics rule or playbook is outside its scope, as it lacks a pipeline for Azure resource activity.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.