Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft security solutions

A security operations team is using Microsoft Sentinel and needs to automate responses to incidents, such as blocking an IP address when a specific alert is triggered. They want to create a playbook that runs automatically. Which component should they use to build the playbook?

⚠ Common exam trap

Many exam-takers confuse Azure Logic Apps with other automation services like Power Automate or Azure Functions, which are not used for Sentinel playbooks.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Azure Logic Apps

Microsoft Sentinel playbooks are automated workflows built on Azure Logic Apps. They allow you to orchestrate responses to incidents using a visual designer and connectors to various services. While other automation tools exist, Logic Apps is the designated platform for Sentinel playbooks, making it the correct choice for this scenario.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Azure Functions

    Why it's wrong here

    Azure Functions is a serverless compute service that can run code in response to events. While it can be used for automation, it is not the primary tool for building Sentinel playbooks. Playbooks specifically use Logic Apps' visual workflow and prebuilt connectors, which simplify integration with security tools.

  • ✗

    Azure Automation runbooks

    Why it's wrong here

    Azure Automation runbooks are used for process automation and configuration management, often with PowerShell or Python. They are not integrated with Microsoft Sentinel's playbook feature. Sentinel playbooks are based on Logic Apps, not Automation runbooks, so this is not the correct choice.

  • ✗

    Microsoft Power Automate

    Why it's wrong here

    Microsoft Power Automate is a separate automation service focused on business workflows. While it shares some underlying technology with Logic Apps, it is not used to create Microsoft Sentinel playbooks. Sentinel playbooks are specifically built with Azure Logic Apps, which offer security-focused connectors and integration with Sentinel.

  • ✓

    Azure Logic Apps

    Why this is correct

    Microsoft Sentinel playbooks are built on Azure Logic Apps. Logic Apps provide a visual designer and connectors to hundreds of services, enabling automated workflows. To automate incident response, you create a Logic App and then associate it with an analytics rule in Sentinel. This is the correct component for building playbooks.

About these practice questions

Courseiva writes every SC-900 question from scratch — 1,279 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.