Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft security solutions

A security operations team uses Microsoft Sentinel to centralize security log analysis. They need to ingest logs from a third-party firewall that does not have a native connector. What should the team use to bring the firewall logs into Microsoft Sentinel?

⚠ Common exam trap

A common mix-up: candidates confuse data connectors (which handle ingestion) with playbooks or workbooks (which handle response or visualization), leading them to select a post-ingestion tool instead of the correct ingestion method.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Data connectors

Microsoft Sentinel uses data connectors to ingest logs from various sources, including third-party devices that lack native connectors. For a firewall without a built-in connector, the team can use the Common Event Format (CEF) connector or Syslog connector, which are both categorized as data connectors. These connectors allow the firewall to forward logs via Syslog or CEF over UDP/TCP, which Sentinel then parses and ingests into the Log Analytics workspace.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Data connectors

    Why this is correct

    Microsoft Sentinel's primary function as a Security Information and Event Management (SIEM) solution relies on ingesting security data from diverse sources. Data connectors are the specific mechanisms that facilitate this ingestion, establishing a secure link between various data sources (like Azure Activity Logs, Microsoft 365 Defender, firewalls, or custom applications) and the Log Analytics workspace underpinning Sentinel. They normalize and stream logs, making them available for analysis, threat detection, and investigation within the platform. For sources without direct API integration, generic connectors like Syslog or Common Event Format (CEF) are utilized to centralize data.

  • Playbooks

    Why it's wrong here

    Microsoft Sentinel playbooks, built on Azure Logic Apps, are designed for Security Orchestration, Automation, and Response (SOAR). They automate incident response tasks, such as enriching alerts with external threat intelligence, blocking malicious IPs, or creating tickets in ITSM systems, typically triggered by analytics rules or manual intervention. While crucial for efficient security operations, playbooks operate on *existing* alerts and incidents within Sentinel and do not perform the initial collection or ingestion of raw security logs from various sources.

    When this WOULD be correct

    A security team needs to automate incident response actions, such as blocking an IP address on a firewall, when a specific alert is triggered in Microsoft Sentinel. Playbooks would be the correct answer.

  • Workbooks

    Why it's wrong here

    Microsoft Sentinel workbooks offer flexible and interactive dashboards for visualizing and monitoring security data. They allow security analysts to create custom reports, track key performance indicators (KPIs), and gain insights into security posture by querying and presenting data from the underlying Log Analytics workspace. While invaluable for data exploration and reporting, workbooks are purely a presentation layer; they consume and display data that has *already been ingested* and processed by Sentinel, rather than performing any data collection themselves.

    When this WOULD be correct

    A security team needs to create a custom dashboard to monitor trends in firewall log data that has already been ingested into Microsoft Sentinel. They should use Workbooks to build interactive visualizations and reports.

  • Analytics rules

    Why it's wrong here

    Analytics rules in Microsoft Sentinel are fundamental for proactive threat detection, leveraging Kusto Query Language (KQL) to define patterns or anomalies within ingested log data. These rules continuously scan the collected logs, generating security alerts and incidents when predefined conditions are met, such as multiple failed login attempts or suspicious process executions. However, their role is solely to analyze and identify threats from data *already present* in the Log Analytics workspace, not to facilitate the initial collection or centralization of that data.

    When this WOULD be correct

    A security team has already ingested firewall logs into Microsoft Sentinel and wants to create automated alerts for suspicious traffic patterns. In that scenario, analytics rules would be the correct choice to define detection logic and trigger incidents.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SC-900 exam frequently reuses these exact scenarios with slightly different constraints.

Data connectorsCorrect answer

Why this is correct

Microsoft Sentinel's primary function as a Security Information and Event Management (SIEM) solution relies on ingesting security data from diverse sources. Data connectors are the specific mechanisms that facilitate this ingestion, establishing a secure link between various data sources (like Azure Activity Logs, Microsoft 365 Defender, firewalls, or custom applications) and the Log Analytics workspace underpinning Sentinel. They normalize and stream logs, making them available for analysis, threat detection, and investigation within the platform. For sources without direct API integration, generic connectors like Syslog or Common Event Format (CEF) are utilized to centralize data.

PlaybooksWrong answer — click to see why

Why this is wrong here

Playbooks are automated response workflows triggered by alerts, not used for ingesting logs from external sources into Microsoft Sentinel.

★ When this WOULD be the correct answer

A security team needs to automate incident response actions, such as blocking an IP address on a firewall, when a specific alert is triggered in Microsoft Sentinel. Playbooks would be the correct answer.

Why candidates choose this

Candidates may confuse playbooks with data connectors because both involve automation, but playbooks handle response actions, not log ingestion.

WorkbooksWrong answer — click to see why

Why this is wrong here

Workbooks are used for visualizing and reporting on data already ingested into Microsoft Sentinel, not for ingesting logs from external sources like a third-party firewall.

★ When this WOULD be the correct answer

A security team needs to create a custom dashboard to monitor trends in firewall log data that has already been ingested into Microsoft Sentinel. They should use Workbooks to build interactive visualizations and reports.

Why candidates choose this

Candidates may confuse Workbooks with data connectors because both involve handling data, but Workbooks are for visualization, not ingestion.

Analytics rulesWrong answer — click to see why

Why this is wrong here

Analytics rules are used to detect threats and generate incidents based on ingested data, not to ingest logs from external sources. They operate on data already in Sentinel, so they cannot bring in firewall logs.

★ When this WOULD be the correct answer

A security team has already ingested firewall logs into Microsoft Sentinel and wants to create automated alerts for suspicious traffic patterns. In that scenario, analytics rules would be the correct choice to define detection logic and trigger incidents.

Why candidates choose this

Candidates may confuse analytics rules with data ingestion mechanisms, thinking that rules can pull in data from external sources, or they may assume that any 'rule' can handle log collection.

Analysis generated from the official SC-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.