SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
Contoso uses Microsoft Sentinel. They want to automate response to a high-severity incident by blocking the source IP in Azure Firewall and sending a notification to the SOC team via email. Which feature should they use?
⚠ Common exam trap
The trap is confusing automation rules with other Sentinel features like Fusion or hunting queries. Candidates might think Fusion handles automation, but it's for incident correlation. The key is that automation rules are specifically for orchestrating responses.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an automation rule.
Microsoft Sentinel automation rules allow you to define triggers and actions based on incident creation or updates. They can automatically run playbooks (Logic Apps) to perform response actions like blocking an IP in Azure Firewall and sending email notifications. Automation rules are designed for orchestration and response, making them the correct choice for automating incident response.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a hunting query.
Why it's wrong here
Creating a hunting query in Microsoft Sentinel is a proactive threat-seeking activity where security analysts manually search for indicators of compromise or anomalous behavior using Kusto Query Language (KQL). While crucial for identifying threats not caught by automated rules, these queries are designed for ad-hoc, interactive exploration and do not inherently provide a mechanism to automatically trigger response actions upon detection. They are analytical tools for human-driven investigation, not automation triggers for incident response workflows.
- ✓
Create an automation rule.
Why this is correct
An automation rule in Microsoft Sentinel is the primary mechanism for orchestrating automated responses to incidents or alerts. These rules allow administrators to define conditions based on incident or alert properties, and then automatically perform actions such as suppressing false positives, assigning incidents, or, most importantly, triggering a playbook (Azure Logic App) to execute complex response workflows. This direct linkage to playbooks is precisely how Contoso can automate its incident response processes.
- ✗
Enable Fusion.
Why it's wrong here
Enabling Fusion in Microsoft Sentinel leverages AI and machine learning to automatically correlate multiple low-fidelity alerts across different products into high-fidelity incidents, significantly reducing alert fatigue and surfacing complex multi-stage attacks. While Fusion enhances detection and incident creation by providing a more comprehensive view of threats, its core function is intelligent correlation and incident generation, not the automated execution of response actions like blocking IPs or isolating hosts. It improves the quality of incidents but doesn't automate the *response* to them.
- ✗
Create a workbook.
Why it's wrong here
Creating a workbook in Microsoft Sentinel involves building interactive dashboards and reports using Kusto Query Language (KQL) to visualize security data, monitor trends, and gain insights into the security posture. Workbooks are powerful tools for data exploration, compliance reporting, and operational monitoring, providing a visual representation of security events and incident metrics. However, they are purely for data presentation and analysis, offering no inherent capability to automatically initiate or execute any incident response actions or workflows.
Go deeper
Related to this question
Learn chapter
Azure Resource Locks: ReadOnly and Delete
Key term
Incident response
Incident response is the structured approach an organization uses to identify, contain, and recover from cybersecurity incidents like data breaches or ransomware attacks.
Key term
Firewall
A firewall is a network security system that monitors and controls incoming and outgoing traffic based on predetermined security rules to protect trusted internal networks from untrusted external networks.
About these practice questions
This SC-900 question is part of Courseiva's 1,279-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.