Courseiva

Using Analytics Rules in Microsoft Sentinel to Automatically Create Incidents

An organization uses Microsoft Sentinel for SIEM. The security operations center (SOC) wants to automatically create an incident when a user account is compromised and suspicious activity is detected. Which Microsoft Sentinel feature should be used?

Quick Answer

The answer is analytics rules, because they are the Microsoft Sentinel feature specifically designed to create incidents from detection logic. When a user account is compromised and suspicious activity is detected, analytics rules evaluate incoming data against predefined or custom queries, and when a match occurs, they automatically generate an incident for the SOC to investigate. On the SC-900 exam, this concept tests your understanding of how Sentinel’s core components map to security operations tasks—analytics rules handle detection and incident creation, while playbooks automate responses, workbooks visualize data, and watchlists enrich threat intelligence. A common trap is confusing analytics rules with playbooks, but remember: rules create the incident, playbooks act on it. For a quick memory tip, think “Rules Raise Incidents”—the R in Rules reminds you they are the trigger for incident generation.

⚠ Common exam trap

Test-takers frequently confuse automation playbooks (which respond to incidents) with analytics rules (which create incidents), leading them to select playbooks for incident creation instead of detection logic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Analytics rules

Analytics rules in Microsoft Sentinel are the correct feature because they define conditions for generating alerts and can automatically create incidents when those conditions are met. In this scenario, an analytics rule can be configured to detect a compromised user account and suspicious activity, then automatically create an incident for the SOC to investigate.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Analytics rules

    Why this is correct

    Analytics rules create incidents from detections.

  • Watchlists

    Why it's wrong here

    Watchlists store external data for correlation.

  • Automation playbooks

    Why it's wrong here

    Playbooks respond to incidents, not create them.

  • Workbooks

    Why it's wrong here

    Workbooks provide dashboards.

Go deeper

Related to this question

About these practice questions

This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

2 more ways this is tested on SC-900

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Your company uses Microsoft Sentinel to centralize security event monitoring. You need to create a custom analytics rule that triggers an alert when a user account is created outside of business hours. Which rule type should you use?

medium
  • A.Microsoft Security incident creation rule
  • B.Anomaly analytics rule
  • C.Near-real-time (NRT) analytics rule
  • D.Scheduled query analytics rule

Why D: A scheduled query analytics rule is the correct choice because it allows you to define a KQL query that runs on a set schedule (e.g., every 5 minutes) and triggers an alert based on conditions such as user account creation events occurring outside of business hours. This rule type is designed for custom detection scenarios where you need to evaluate log data against specific time-based or threshold-based criteria, making it ideal for monitoring user creation events with a custom schedule.

Variation 2. A company uses Microsoft Sentinel to centralize security logs. They want to correlate AWS CloudTrail logs with Azure AD sign-in logs. Which Microsoft Sentinel feature should they use?

medium
  • A.Workbooks
  • B.Playbooks
  • C.Analytics rules
  • D.Hunting

Why C: Analytics rules in Microsoft Sentinel are designed to correlate and analyze data from multiple sources, such as AWS CloudTrail and Azure AD sign-in logs, to detect security threats. By creating a multi-source analytics rule, you can define conditions that trigger alerts when suspicious patterns emerge across these disparate log streams, enabling centralized threat detection.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.