Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft security solutions

Contoso uses Microsoft Sentinel. They want to automate response to a high-severity incident by blocking the source IP in Azure Firewall and sending a notification to the SOC team via email. Which feature should they use?

⚠ Common exam trap

The trap is confusing automation rules with other Sentinel features like Fusion or hunting queries. Candidates might think Fusion handles automation, but it's for incident correlation. The key is that automation rules are specifically for orchestrating responses.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create an automation rule.

Microsoft Sentinel automation rules allow you to define triggers and actions based on incident creation or updates. They can automatically run playbooks (Logic Apps) to perform response actions like blocking an IP in Azure Firewall and sending email notifications. Automation rules are designed for orchestration and response, making them the correct choice for automating incident response.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a hunting query.

    Why it's wrong here

    Creating a hunting query in Microsoft Sentinel is a proactive threat-seeking activity where security analysts manually search for indicators of compromise or anomalous behavior using Kusto Query Language (KQL). While crucial for identifying threats not caught by automated rules, these queries are designed for ad-hoc, interactive exploration and do not inherently provide a mechanism to automatically trigger response actions upon detection. They are analytical tools for human-driven investigation, not automation triggers for incident response workflows.

  • ✓

    Create an automation rule.

    Why this is correct

    An automation rule in Microsoft Sentinel is the primary mechanism for orchestrating automated responses to incidents or alerts. These rules allow administrators to define conditions based on incident or alert properties, and then automatically perform actions such as suppressing false positives, assigning incidents, or, most importantly, triggering a playbook (Azure Logic App) to execute complex response workflows. This direct linkage to playbooks is precisely how Contoso can automate its incident response processes.

  • ✗

    Enable Fusion.

    Why it's wrong here

    Enabling Fusion in Microsoft Sentinel leverages AI and machine learning to automatically correlate multiple low-fidelity alerts across different products into high-fidelity incidents, significantly reducing alert fatigue and surfacing complex multi-stage attacks. While Fusion enhances detection and incident creation by providing a more comprehensive view of threats, its core function is intelligent correlation and incident generation, not the automated execution of response actions like blocking IPs or isolating hosts. It improves the quality of incidents but doesn't automate the *response* to them.

  • ✗

    Create a workbook.

    Why it's wrong here

    Creating a workbook in Microsoft Sentinel involves building interactive dashboards and reports using Kusto Query Language (KQL) to visualize security data, monitor trends, and gain insights into the security posture. Workbooks are powerful tools for data exploration, compliance reporting, and operational monitoring, providing a visual representation of security events and incident metrics. However, they are purely for data presentation and analysis, offering no inherent capability to automatically initiate or execute any incident response actions or workflows.

Go deeper

Related to this question

About these practice questions

This SC-900 question is part of Courseiva's 1,279-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.