Courseiva

SC-200 Manage a security operations environment Practice Question

Your SOC is implementing a Microsoft Sentinel workspace with multiple content hub solutions. You need to ensure that only approved analytics rules are enabled and that any custom rules are reviewed before activation. Which THREE actions should you take?

⚠ Common exam trap

Many candidates confuse the purpose of the Threat Intelligence - TAXII connector (which imports threat indicators, not rules) or think that the Hunting blade can serve as a governance mechanism for analytics rules, when in fact it is only for ad-hoc threat hunting.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use Microsoft Sentinel Repositories (CI/CD) to manage analytics rules via Azure DevOps or GitHub.

Option C is correct because Microsoft Sentinel Repositories enable CI/CD-based deployment of analytics rules from Azure DevOps or GitHub, so every rule change goes through a pull request and review before activation, enforcing the approval workflow. Option D is correct because installing only Content hub solutions that contain approved analytics rules ensures that only vetted, Microsoft-published or approved rule templates are deployed into the workspace, preventing unapproved content from being enabled. Option E is correct because an automation rule triggered on analytics rule creation can immediately disable any rule not present in the approved list, providing a runtime guardrail that catches rules created outside the governed pipeline. Option A is not correct because the Threat Intelligence - TAXII connector imports threat indicators, not analytics rules, so it does not govern rule enablement. Option B is not correct because hunting queries are separate from analytics rules and do not satisfy the requirement to control which analytics rules are enabled or reviewed.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure Threat Intelligence - Taxii connector to import rules from an external feed.

    Why it's wrong here

    The Threat Intelligence - TAXII connector is a data connector that ingests threat intelligence indicators (STIX objects) from external feeds into Microsoft Sentinel. It does not import, manage, or deploy analytics rules; analytics rules are KQL query definitions stored in workspace configuration. Therefore, configuring this connector cannot address the requirement to control which analytics rules are deployed.

  • ✗

    Use the Hunting blade to create custom hunting queries instead of analytics rules.

    Why it's wrong here

    The Hunting blade is designed for interactive, ad-hoc KQL queries to proactively search for anomalies and does not produce alerts or incidents by itself. While a hunting query can be converted into an analytics rule, doing so is a manual step and does not provide a governance mechanism to vet or approve rules. Using hunting queries instead of analytics rules would bypass scheduled detection and automated incident generation entirely.

  • ✓

    Use Microsoft Sentinel Repositories (CI/CD) to manage analytics rules via Azure DevOps or GitHub.

    Why this is correct

    Microsoft Sentinel Repositories (CI/CD) enables you to manage analytics rules as code in Azure DevOps or GitHub, with content deployed via ARM templates or Bicep. This enforces a formal approval workflow through pull requests and branch policies before any rule reaches the workspace, ensuring only reviewed and approved rules are deployed. It also provides version control and rollback capabilities, making it the most robust governance approach for rule lifecycle management.

  • ✓

    In Content hub, install only the solutions that contain approved analytics rules.

    Why this is correct

    The Content hub offers solutions that bundle analytics rules, data connectors, workbooks, and playbooks, and you can selectively install only solutions containing rules that have been pre-approved by your security team. Installing only those solutions ensures no unapproved rule content is introduced, but it is limited to rules provided in published solutions rather than custom-developed rules. This is a valid guardrail for out-of-the-box content but does not govern custom rule changes made directly in the workspace.

  • ✓

    Create an automation rule that disables any newly created analytics rule that is not in an approved list.

    Why this is correct

    An automation rule can be configured to run whenever an analytics rule is created, and a condition can check if the rule name or ID is not in an approved list, triggering an action to disable that rule. This serves as a reactive safety net to block or disable non-approved rules that may be created directly in the portal, even if CI/CD is not used. However, it relies on maintaining an accurate approved list and is not a substitute for a proactive deployment review process.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.