Drag steps to the numbered slots on the right, or tap a step then tap a slot.
SC-900 Describe the capabilities of Microsoft Entra Practice Question
Sequence the steps to set up Microsoft Sentinel for a new workspace.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
Create Log Analytics workspace → Enable Microsoft Sentinel → Connect data sources → Create analytics rules → Set up automation
Setting up Sentinel requires a Log Analytics workspace, enabling Sentinel, connecting sources, creating rules, and automating responses.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create Log Analytics workspace → Enable Microsoft Sentinel → Connect data sources → Create analytics rules → Set up automation
Why this is correct
This sequence correctly establishes the foundational components of Microsoft Sentinel. First, a Log Analytics workspace is created to serve as the data repository. Next, Microsoft Sentinel is enabled on this workspace, transforming it into a SIEM solution. Subsequently, various data sources are connected to ingest security logs. With data flowing in, analytics rules are then created to detect threats and generate incidents, followed by setting up automation to orchestrate responses to these detected security events.
- ✗
Create Log Analytics workspace → Connect data sources → Enable Microsoft Sentinel → Create analytics rules → Set up automation
Why it's wrong here
This order is incorrect because connecting security-specific data sources typically requires Microsoft Sentinel to be enabled on the Log Analytics workspace first. Many Sentinel data connectors leverage the SIEM capabilities and schema extensions that are only present once Sentinel is active. Attempting to ingest security data before Sentinel is enabled means the workspace is not fully prepared to process and categorize that specific security telemetry.
- ✗
Create Log Analytics workspace → Enable Microsoft Sentinel → Create analytics rules → Connect data sources → Set up automation
Why it's wrong here
This sequence is flawed because creating analytics rules before connecting data sources renders the rules ineffective. Analytics rules are designed to query and analyze ingested security logs to identify threats. Without any data sources connected to the Log Analytics workspace, there is no security telemetry for the analytics rules to evaluate, meaning they cannot detect anomalies or generate incidents.
- ✗
Create Log Analytics workspace → Enable Microsoft Sentinel → Connect data sources → Set up automation → Create analytics rules
Why it's wrong here
This order is incorrect because automation in Microsoft Sentinel, primarily through playbooks and automation rules, typically responds to incidents generated by analytics rules. Setting up automation *before* creating analytics rules means there are no defined threat detection mechanisms to trigger automated responses. Automation needs the context and triggers provided by analytics rules to perform meaningful security operations.
Go deeper
Related to this question
Learn chapter
Microsoft Entra ID
Key term
Microsoft Sentinel
Microsoft Sentinel is a cloud-native security information and event management (SIEM) and security orchestration automation and response (SOAR) service that helps organizations detect, investigate, and respond to cyber threats across their entire digital estate.
About these practice questions
This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.