SC-200 Manage a security operations environment Practice Question
Your organization uses Microsoft Sentinel with Azure Policy. You need to ensure that new Log Analytics workspaces are automatically connected to Sentinel and configured with a standard set of data connectors. What should you use?
⚠ Common exam trap
Watch out — candidates often confuse automation rules (which handle incident response within Sentinel) with Azure Policy (which handles resource provisioning and compliance), leading candidates to incorrectly choose option B.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create Azure Policy definitions that deploy Sentinel and data connectors.
Azure Policy can be used to automatically deploy and configure Microsoft Sentinel and its data connectors on new Log Analytics workspaces. By creating policy definitions with 'DeployIfNotExists' or 'Modify' effects, you ensure that any new workspace is automatically onboarded to Sentinel and has the required data connectors installed, meeting the requirement for automated, consistent configuration at scale.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Deploy an ARM template to each new workspace manually.
Why it's wrong here
Manually deploying an ARM template to each new workspace is operationally unscalable and doesn't enforce ongoing compliance; if a workspace ships without the template run, Sentinel stays disabled. While ARM templates are the right underlying mechanism, Azure Policy's DeployIfNotExists effect automatically executes the template at resource creation and remediates existing resources, removing the need for humans to trigger each deployment.
- ✗
Use Sentinel automation rules to configure new workspaces.
Why it's wrong here
Sentinel automation rules operate on inbound incidents within an already-onboarded workspace — they can assign, tag, or run playbooks, but they have no Azure Resource Manager access to enable Sentinel on a new Log Analytics workspace. They are not a provisioning mechanism and cannot create or configure workspaces; their execution scope is incident data, not Azure resource lifecycle events.
- ✗
Develop a Logic App that runs on a schedule to check for new workspaces.
Why it's wrong here
A scheduled Logic App that polls for new workspaces creates latency and drift, since any workspace created between runs will remain unconfigured until the next poll; it also requires custom idempotency, error handling, and a managed identity to deploy templates. Azure Policy, by contrast, listens to ARM resource creation events and reacts immediately with DeployIfNotExists, making it a native governance control instead of a best-effort polling job.
- ✓
Create Azure Policy definitions that deploy Sentinel and data connectors.
Why this is correct
Azure Policy definitions with the DeployIfNotExists effect automatically enable Sentinel on Log Analytics workspaces by deploying the Sentinel solution, and can embed ARM templates to install data connectors, using a system-assigned managed identity for role assignment. This is the recommended at-scale governance approach because it continuously evaluates new and existing workspaces, auto-remediates non-compliant resources, and reports compliance status in Azure Policy.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.