SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
You are a security operations manager for Northwind Traders. The company uses Microsoft Sentinel as its SIEM. You need to create a detection rule that triggers an incident when a user account is added to the Domain Admins group. The rule should only trigger for changes made outside of approved maintenance windows. Which Sentinel feature should you use to implement this logic?
⚠ Common exam trap
The trap here is thinking that built-in detections from Defender for Identity or Fusion rules can be customized with maintenance window exclusions, when only scheduled analytics rules offer that level of control.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Scheduled analytics rule with a KQL query that filters out events during maintenance windows.
A scheduled analytics rule in Microsoft Sentinel allows you to run a KQL query on a schedule. By incorporating logic to exclude events during maintenance windows, you can ensure the rule only triggers for unauthorized changes. This provides the flexibility to customize detection criteria and reduce false positives from known maintenance activities.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Scheduled analytics rule with a KQL query that filters out events during maintenance windows.
Why this is correct
Scheduled analytics rules in Microsoft Sentinel allow you to run KQL queries at regular intervals to detect specific events. You can include logic in the query to exclude events that occur during approved maintenance windows, for example by checking the timestamp against a known schedule. This enables precise detection of unauthorized group membership changes.
- ✗
Microsoft Defender for Identity sensor that automatically detects privileged group modifications.
Why it's wrong here
Microsoft Defender for Identity can detect suspicious modifications to privileged groups, but it does not allow you to customize detection logic to exclude specific maintenance windows. It generates its own alerts based on built-in behavioral analytics. While it can be integrated with Sentinel, it does not provide the granular control needed for this scenario.
- ✗
Workbook that visualizes group membership changes over time.
Why it's wrong here
Workbooks in Microsoft Sentinel are used for visualization and reporting, not for creating detection rules that trigger incidents. They can display data from logs, but they do not evaluate conditions or generate alerts. Workbooks are passive monitoring tools, not active detection mechanisms. Therefore, they cannot implement the required logic.
- ✗
Fusion rule that uses machine learning to correlate alerts.
Why it's wrong here
Fusion rules are designed to detect multi-stage attacks by correlating low-fidelity alerts from various sources. They do not provide a way to filter events based on maintenance windows or to create custom detection logic for a specific group membership change. Fusion is for advanced correlation, not for custom scheduled queries with time-based exclusions.
Go deeper
Related to this question
Learn chapter
Compliance Manager
Key term
User account
A user account is a digital identity that allows a person to access a computer system, network, or application with specific permissions and settings.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
One of 1,279 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.