SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
Which THREE actions can Microsoft Sentinel perform as part of automated incident response using playbooks?
⚠ Common exam trap
A common mix-up: candidates assume Sentinel can automate every possible IT action directly. Sentinel playbooks rely on external connectors and APIs, and actions like installing anti-malware software are not supported by standard connectors. Do not confuse Sentinel automation with endpoint management or direct infrastructure changes that require additional configuration.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Block an IP address on a firewall
Microsoft Sentinel playbooks are built on Azure Logic Apps, so they can call connectors and REST APIs to take remediation and ticketing actions automatically. Option A is correct because a playbook can invoke a firewall connector or API to block a malicious IP address identified in an incident. Option C is correct because a playbook can call Microsoft Entra ID or Microsoft Graph actions to reset a compromised user's password as part of containment. Option D is correct because a playbook can use the ServiceNow connector to create an incident ticket, integrating Sentinel with ITSM workflows. Option B is not a typical Sentinel playbook action, since installing anti-malware on a device is an endpoint-management task handled by tools such as Microsoft Defender for Endpoint or Intune. Option E, while technically possible through Azure Resource Manager or Logic Apps, is not one of the three most common Sentinel playbook response actions: blocking an IP address, resetting a user password, and creating a ServiceNow ticket.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Block an IP address on a firewall
Why this is correct
Playbooks are Logic Apps, so they can call the firewall's connector or REST API to add a deny rule for the offending address, satisfying the requirement for an automated containment action rather than only notification or enrichment.
- ✗
Install anti-malware software on a device
Why it's wrong here
Playbooks do not have direct capability to install software.
- ✓
Reset a user's password
Why this is correct
Playbooks, built on Azure Logic Apps, can call Microsoft Graph or Microsoft Entra ID connectors to reset a user's password directly, satisfying the requirement for automated remediation rather than mere notification. This makes it a valid Sentinel response action, since the connector performs the reset without analyst intervention.
- ✓
Create an incident in ServiceNow
Why this is correct
Playbooks, built on Azure Logic Apps, connect to external systems through connectors, so Microsoft Sentinel can raise a ServiceNow incident automatically when an analytics rule triggers. This satisfies the automated incident response requirement by pushing incident data into the ITSM platform, ensuring ticketing and tracking occur without manual intervention.
- ✗
Modify a network security group rule
Why it's wrong here
Playbooks can trigger automation to modify NSG rules, but not directly.
Go deeper
Related to this question
Learn chapter
Microsoft Defender for Cloud Apps
Key term
Microsoft Defender
Microsoft Defender is a suite of security products that protects devices, data, and identities from cyber threats like malware, phishing, and unauthorized access.
Key term
Malware
Malware is any software intentionally designed to cause damage, disrupt operations, steal data, or gain unauthorized access to computer systems.
About these practice questions
This SC-900 question is part of Courseiva's 1,279-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.