SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
A security operations team is using Microsoft Sentinel and needs to automate responses to incidents, such as blocking an IP address when a specific alert is triggered. They want to create a playbook that runs automatically. Which component should they use to build the playbook?
⚠ Common exam trap
Many exam-takers confuse Azure Logic Apps with other automation services like Power Automate or Azure Functions, which are not used for Sentinel playbooks.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Azure Logic Apps
Microsoft Sentinel playbooks are automated workflows built on Azure Logic Apps. They allow you to orchestrate responses to incidents using a visual designer and connectors to various services. While other automation tools exist, Logic Apps is the designated platform for Sentinel playbooks, making it the correct choice for this scenario.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Azure Functions
Why it's wrong here
Azure Functions is a serverless compute service that can run code in response to events. While it can be used for automation, it is not the primary tool for building Sentinel playbooks. Playbooks specifically use Logic Apps' visual workflow and prebuilt connectors, which simplify integration with security tools.
- ✗
Azure Automation runbooks
Why it's wrong here
Azure Automation runbooks are used for process automation and configuration management, often with PowerShell or Python. They are not integrated with Microsoft Sentinel's playbook feature. Sentinel playbooks are based on Logic Apps, not Automation runbooks, so this is not the correct choice.
- ✗
Microsoft Power Automate
Why it's wrong here
Microsoft Power Automate is a separate automation service focused on business workflows. While it shares some underlying technology with Logic Apps, it is not used to create Microsoft Sentinel playbooks. Sentinel playbooks are specifically built with Azure Logic Apps, which offer security-focused connectors and integration with Sentinel.
- ✓
Azure Logic Apps
Why this is correct
Microsoft Sentinel playbooks are built on Azure Logic Apps. Logic Apps provide a visual designer and connectors to hundreds of services, enabling automated workflows. To automate incident response, you create a Logic App and then associate it with an analytics rule in Sentinel. This is the correct component for building playbooks.
Go deeper
Related to this question
Learn chapter
Security Operations Model and SOC Functions
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Alert
An alert is a notification that something unusual or potentially harmful has happened in a computer system or network.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,279 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.