Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft security solutions

Which THREE actions can Microsoft Sentinel perform as part of automated incident response using playbooks?

⚠ Common exam trap

A common mix-up: candidates assume Sentinel can automate every possible IT action directly. Sentinel playbooks rely on external connectors and APIs, and actions like installing anti-malware software are not supported by standard connectors. Do not confuse Sentinel automation with endpoint management or direct infrastructure changes that require additional configuration.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Block an IP address on a firewall

Microsoft Sentinel playbooks are built on Azure Logic Apps, so they can call connectors and REST APIs to take remediation and ticketing actions automatically. Option A is correct because a playbook can invoke a firewall connector or API to block a malicious IP address identified in an incident. Option C is correct because a playbook can call Microsoft Entra ID or Microsoft Graph actions to reset a compromised user's password as part of containment. Option D is correct because a playbook can use the ServiceNow connector to create an incident ticket, integrating Sentinel with ITSM workflows. Option B is not a typical Sentinel playbook action, since installing anti-malware on a device is an endpoint-management task handled by tools such as Microsoft Defender for Endpoint or Intune. Option E, while technically possible through Azure Resource Manager or Logic Apps, is not one of the three most common Sentinel playbook response actions: blocking an IP address, resetting a user password, and creating a ServiceNow ticket.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Block an IP address on a firewall

    Why this is correct

    Playbooks are Logic Apps, so they can call the firewall's connector or REST API to add a deny rule for the offending address, satisfying the requirement for an automated containment action rather than only notification or enrichment.

  • ✗

    Install anti-malware software on a device

    Why it's wrong here

    Playbooks do not have direct capability to install software.

  • ✓

    Reset a user's password

    Why this is correct

    Playbooks, built on Azure Logic Apps, can call Microsoft Graph or Microsoft Entra ID connectors to reset a user's password directly, satisfying the requirement for automated remediation rather than mere notification. This makes it a valid Sentinel response action, since the connector performs the reset without analyst intervention.

  • ✓

    Create an incident in ServiceNow

    Why this is correct

    Playbooks, built on Azure Logic Apps, connect to external systems through connectors, so Microsoft Sentinel can raise a ServiceNow incident automatically when an analytics rule triggers. This satisfies the automated incident response requirement by pushing incident data into the ITSM platform, ensuring ticketing and tracking occur without manual intervention.

  • ✗

    Modify a network security group rule

    Why it's wrong here

    Playbooks can trigger automation to modify NSG rules, but not directly.

About these practice questions

This SC-900 question is part of Courseiva's 1,279-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.