Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft security solutions

Contoso uses Microsoft Sentinel. They want to automate response to a high-severity incident by blocking the source IP in Azure Firewall and sending a notification to the SOC team via email. Which feature should they use?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Create an automation rule.

Correct: Automation rules in Microsoft Sentinel can automatically trigger playbooks (e.g., to block an IP in Azure Firewall) and send notifications based on incident creation or update, meeting the requirement. Option A (hunting query) is for proactively searching for threats, not automated response. Option C (Fusion) is a correlation engine that detects multistage attacks but does not automate actions. Option D (workbook) is for visualization and reporting, not automation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Create a hunting query.

    Why it's wrong here

    Creating a hunting query in Microsoft Sentinel is a proactive threat-seeking activity where security analysts manually search for indicators of compromise or anomalous behavior using Kusto Query Language (KQL). While crucial for identifying threats not caught by automated rules, these queries are designed for ad-hoc, interactive exploration and do not inherently provide a mechanism to automatically trigger response actions upon detection. They are analytical tools for human-driven investigation, not automation triggers for incident response workflows.

  • Create an automation rule.

    Why this is correct

    An automation rule in Microsoft Sentinel is the primary mechanism for orchestrating automated responses to incidents or alerts. These rules allow administrators to define conditions based on incident or alert properties, and then automatically perform actions such as suppressing false positives, assigning incidents, or, most importantly, triggering a playbook (Azure Logic App) to execute complex response workflows. This direct linkage to playbooks is precisely how Contoso can automate its incident response processes.

  • Enable Fusion.

    Why it's wrong here

    Enabling Fusion in Microsoft Sentinel leverages AI and machine learning to automatically correlate multiple low-fidelity alerts across different products into high-fidelity incidents, significantly reducing alert fatigue and surfacing complex multi-stage attacks. While Fusion enhances detection and incident creation by providing a more comprehensive view of threats, its core function is intelligent correlation and incident generation, not the automated execution of response actions like blocking IPs or isolating hosts. It improves the quality of incidents but doesn't automate the *response* to them.

  • Create a workbook.

    Why it's wrong here

    Creating a workbook in Microsoft Sentinel involves building interactive dashboards and reports using Kusto Query Language (KQL) to visualize security data, monitor trends, and gain insights into the security posture. Workbooks are powerful tools for data exploration, compliance reporting, and operational monitoring, providing a visual representation of security events and incident metrics. However, they are purely for data presentation and analysis, offering no inherent capability to automatically initiate or execute any incident response actions or workflows.

Go deeper

Related to this question

About these practice questions

This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.