Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft security solutions

You are a security operations manager for Northwind Traders. The company uses Microsoft Sentinel as its SIEM. You need to create a detection rule that triggers an incident when a user account is added to the Domain Admins group. The rule should only trigger for changes made outside of approved maintenance windows. Which Sentinel feature should you use to implement this logic?

⚠ Common exam trap

The trap here is thinking that built-in detections from Defender for Identity or Fusion rules can be customized with maintenance window exclusions, when only scheduled analytics rules offer that level of control.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Scheduled analytics rule with a KQL query that filters out events during maintenance windows.

A scheduled analytics rule in Microsoft Sentinel allows you to run a KQL query on a schedule. By incorporating logic to exclude events during maintenance windows, you can ensure the rule only triggers for unauthorized changes. This provides the flexibility to customize detection criteria and reduce false positives from known maintenance activities.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Scheduled analytics rule with a KQL query that filters out events during maintenance windows.

    Why this is correct

    Scheduled analytics rules in Microsoft Sentinel allow you to run KQL queries at regular intervals to detect specific events. You can include logic in the query to exclude events that occur during approved maintenance windows, for example by checking the timestamp against a known schedule. This enables precise detection of unauthorized group membership changes.

  • ✗

    Microsoft Defender for Identity sensor that automatically detects privileged group modifications.

    Why it's wrong here

    Microsoft Defender for Identity can detect suspicious modifications to privileged groups, but it does not allow you to customize detection logic to exclude specific maintenance windows. It generates its own alerts based on built-in behavioral analytics. While it can be integrated with Sentinel, it does not provide the granular control needed for this scenario.

  • ✗

    Workbook that visualizes group membership changes over time.

    Why it's wrong here

    Workbooks in Microsoft Sentinel are used for visualization and reporting, not for creating detection rules that trigger incidents. They can display data from logs, but they do not evaluate conditions or generate alerts. Workbooks are passive monitoring tools, not active detection mechanisms. Therefore, they cannot implement the required logic.

  • ✗

    Fusion rule that uses machine learning to correlate alerts.

    Why it's wrong here

    Fusion rules are designed to detect multi-stage attacks by correlating low-fidelity alerts from various sources. They do not provide a way to filter events based on maintenance windows or to create custom detection logic for a specific group membership change. Fusion is for advanced correlation, not for custom scheduled queries with time-based exclusions.

About these practice questions

One of 1,279 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.