SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
A company uses Microsoft Sentinel as its SIEM. The security team wants to automatically trigger a playbook when a high-severity incident is created. Which automation option should be used?
⚠ Common exam trap
It's easy for candidates to confuse the automation rule (the trigger condition in Sentinel) with the playbook itself (the workflow logic), or mistakenly think a generic HTTP trigger or Power Automate flow can replace Sentinel's built-in incident-based automation rule.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Automation rule in Microsoft Sentinel
Microsoft Sentinel automation rules are specifically designed to trigger automated responses—such as running playbooks—based on incident creation or update conditions, including severity level. When a high-severity incident is created, an automation rule can invoke a playbook without requiring manual intervention or external orchestration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Azure Policy assignment
Why it's wrong here
Azure Policy is a governance tool used to enforce organizational standards and assess compliance for Azure resources by defining rules for their configurations. It focuses on ensuring resources meet specific requirements (e.g., tagging, allowed locations) rather than providing real-time, automated incident response capabilities or triggering security playbooks based on SIEM alerts in Microsoft Sentinel. Its primary function is resource governance, not operational security automation.
- ✗
Microsoft Power Automate flow directly from Sentinel
Why it's wrong here
Microsoft Sentinel's native automation for security incident response, known as playbooks, is fundamentally built upon Azure Logic Apps. While Microsoft Power Automate is a robust platform for general workflow automation, it does not have a direct, integrated mechanism within Sentinel to serve as a playbook for automated incident handling. This distinguishes it from the enterprise-grade, event-driven capabilities of Logic Apps specifically designed for Azure services and Sentinel's SOAR framework.
- ✓
Automation rule in Microsoft Sentinel
Why this is correct
Automation rules in Microsoft Sentinel are the core mechanism for orchestrating automated responses to security incidents and alerts, streamlining the Security Orchestration, Automation, and Response (SOAR) process. These rules allow security teams to define specific conditions (e.g., incident severity, associated entities) that, when met, will automatically trigger a pre-configured playbook (an Azure Logic App), assign incidents, change their status, or close them. This significantly enhances response efficiency and consistency by automating repetitive tasks.
- ✗
Azure Logic Apps HTTP trigger
Why it's wrong here
While an Azure Logic App can indeed be configured to start via an HTTP Request trigger, allowing it to be invoked by an external HTTP call, this method bypasses Microsoft Sentinel's native incident response framework. It lacks the integrated context and automatic triggering capabilities that Sentinel's automation rules provide, which are essential for seamlessly passing incident-specific data and orchestrating playbooks directly from security incidents. Relying solely on an HTTP trigger would require custom integration logic outside of Sentinel's SOAR capabilities.
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
SIEM
SIEM (Security Information and Event Management) is a system that collects and analyzes log data from across an IT environment to detect and respond to security threats in real time.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.