Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft security solutions

An organization uses Microsoft Sentinel for security information and event management (SIEM) and security orchestration automated response (SOAR). They want to automatically respond to a specific incident by running a playbook. What should they configure?

⚠ Common exam trap

Watch out — candidates often confuse analytics rules with automation rules, thinking that analytics rules can directly run playbooks, but in Sentinel, analytics rules only generate alerts, and automation rules are the mechanism to attach playbooks to incidents.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Automation rule

Automation rules in Microsoft Sentinel allow you to define automated responses to incidents, including running playbooks. When an incident is created or updated, an automation rule can trigger a playbook (a collection of automated workflows based on Azure Logic Apps) to perform actions such as blocking a user or isolating a machine, directly addressing the requirement to automatically respond to a specific incident.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Automation rule

    Why this is correct

    Automation rules in Microsoft Sentinel are designed to orchestrate and automate incident response workflows. They allow security operations teams to define conditions based on incident properties (e.g., severity, specific entities) and then automatically perform actions, such as running a playbook, assigning an incident, or changing its status. This capability is crucial for reducing manual effort and accelerating response times to security threats.

  • Workbook

    Why it's wrong here

    Workbooks in Microsoft Sentinel are interactive dashboards that aggregate data from various sources, including logs and incidents, to provide visual insights into an organization's security posture. While they are excellent for monitoring, reporting, and threat investigation by presenting data graphically, they do not inherently trigger automated actions or responses to incidents. Their primary function is data visualization and analysis, not automation.

  • Hunting query

    Why it's wrong here

    Hunting queries in Microsoft Sentinel are Kusto Query Language (KQL) statements used by security analysts to proactively search for threats, anomalies, and suspicious activities within their log data that might not have been detected by automated rules. These queries are a manual, investigative tool for uncovering stealthy threats, but they do not automatically initiate incident responses or trigger playbooks; they require human execution and interpretation.

  • Analytics rule

    Why it's wrong here

    Analytics rules in Microsoft Sentinel are configured to detect specific threats or suspicious activities by continuously querying log data. When the conditions defined in an analytics rule are met, it generates security alerts, which can then be grouped into incidents. While an analytics rule is the source of an alert, it does not directly automate the response to the resulting incident; that function is delegated to automation rules and playbooks.

About these practice questions

One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.