SC-200 Manage a security operations environment Practice Question
Your organization uses Microsoft Sentinel. You need to ensure that an alert is created when a user accesses a sensitive SharePoint site from an unusual location. What should you create?
⚠ Common exam trap
A common mix-up: candidates confuse the purpose of an analytics rule (alert creation) with automation rules (incident management) or playbooks (response actions), leading them to select a post-alert component instead of the rule that actually generates the alert.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
An analytics rule
An analytics rule in Microsoft Sentinel defines the conditions under which alerts are generated. To detect a user accessing a sensitive SharePoint site from an unusual location, you would create an analytics rule that queries the Office 365 activity logs (e.g., SharePoint operations) and uses the 'Unusual Geo-Location' anomaly detection or a custom KQL query comparing the user's location against a baseline of their typical access patterns. This rule will then generate an alert when the condition is met.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A watchlist
Why it's wrong here
A watchlist in Microsoft Sentinel stores structured reference data (such as CSV or TSV files) that you can join or look up in KQL queries to enrich detections or hunts. It is purely a passive data store and has no built-in alerting engine, so it cannot by itself detect suspicious behavior or generate alerts; you would need to reference it from an analytics rule to drive detection.
- ✓
An analytics rule
Why this is correct
An analytics rule is the correct choice because Microsoft Sentinel uses analytics rules as its primary detection mechanism. A scheduled or Microsoft security analytics rule runs KQL queries on a recurring basis, evaluates results against thresholds or entity behavior, and can generate alerts and incidents for suspicious sign-in patterns or other anomalies, thereby satisfying the requirement to ensure detection and alerting.
- ✗
A playbook
Why it's wrong here
A playbook in Sentinel is an Azure Logic Apps–based workflow that executes automated response actions when invoked by an alert or incident, such as isolating an asset, collecting evidence, or sending notifications. It does not perform threat detection or data querying on its own, so it cannot create alerts based on suspicious access patterns; it only reacts after a detection has already occurred.
- ✗
An automation rule
Why it's wrong here
An automation rule in Microsoft Sentinel is designed to manage incident operations after an alert or incident is created—for example, changing status, assigning ownership, adding tags, or triggering playbooks. Although it can respond to the creation of alerts, it does not contain detection logic and cannot generate new alerts or identify suspicious access patterns, so it is not the mechanism that ensures detection.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.