Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft security solutions

Your organization is planning to use Microsoft Sentinel as a SIEM solution. Which TWO of the following are required components for Sentinel? (Select TWO.)

⚠ Common exam trap

Many exam-takers confuse optional but highly recommended components (like playbooks, workbooks, and custom KQL rules) with the absolute foundational requirements (a Log Analytics workspace and data connectors), leading them to select more than two answers or miss the core prerequisites.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A Log Analytics workspace

Microsoft Sentinel is built on top of Azure Monitor Logs, so option A, a Log Analytics workspace, is required because it is the underlying data store where all ingested security events, alerts, and incidents are collected, queried with KQL, and retained. Option C, data connectors to ingest security data, is also required because Sentinel must receive telemetry from sources such as Microsoft 365 Defender, Azure Activity, AWS, or syslog before analytics rules, incidents, or hunting queries can operate on that data. Playbooks (B) are optional SOAR components used for automated response, workbooks (D) are optional visualization tools for dashboards, and KQL queries (E) are used within analytics rules or hunting but are not a separate required deployment component beyond the workspace and ingestion path.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    A Log Analytics workspace

    Why this is correct

    Microsoft Sentinel is fundamentally built upon and deployed within an Azure Log Analytics workspace. This workspace serves as the central repository for all ingested security data, including logs from various sources, and provides the underlying data platform for Sentinel's analytics, threat detection, and investigation capabilities. Without an existing or newly created Log Analytics workspace, Microsoft Sentinel cannot be provisioned or function.

  • ✗

    A playbook for automated response

    Why it's wrong here

    While playbooks, powered by Azure Logic Apps, are a powerful feature for automating responses to security incidents within Microsoft Sentinel, they are not a mandatory component for Sentinel's initial deployment or core operation. Sentinel can ingest data, detect threats, and allow for manual investigation without any playbooks configured, making them an optional enhancement for automation.

  • ✓

    Data connectors to ingest security data

    Why this is correct

    Data connectors are essential for Microsoft Sentinel to function effectively as a Security Information and Event Management (SIEM) solution. These connectors facilitate the ingestion of security logs and events from various sources, such as Azure services, other cloud providers, and on-premises systems, into the underlying Log Analytics workspace. Without data connectors, Sentinel would have no security data to analyze, detect threats from, or investigate, rendering it ineffective.

  • ✗

    A workbook for dashboards

    Why it's wrong here

    Workbooks in Microsoft Sentinel provide flexible and interactive dashboards for visualizing security data and insights, often used for monitoring and hunting. However, they are an optional feature and not a prerequisite for Sentinel's core functionality, such as data ingestion, threat detection, or incident management. Sentinel can operate fully without any custom workbooks being created or utilized.

  • ✗

    A KQL query for threat detection

    Why it's wrong here

    Kusto Query Language (KQL) queries are indeed fundamental to how Microsoft Sentinel operates, powering analytics rules, hunting queries, and data exploration. However, a specific KQL query itself is not a foundational component that must be provisioned for Sentinel to exist or begin functioning. Sentinel comes with built-in analytics rules and capabilities; users write KQL queries to enhance or customize detection, but Sentinel doesn't require a user-defined KQL query as a core setup element.

About these practice questions

This SC-900 question is part of Courseiva's 1,279-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.