SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
Your organization is using Microsoft Sentinel as a SIEM. You want to automatically respond to a high-severity incident by opening a ticket in ServiceNow and notifying the security team via email. What should you create?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
An automation rule
Automation rules in Microsoft Sentinel can be configured to trigger automated responses when an incident is created, such as running a playbook (a Logic App) that opens a ticket in ServiceNow and sends an email notification. Option B is wrong because workbooks are for visualization and reporting, not automation. Option C is wrong because analytics rules generate alerts/incidents based on data queries, but they do not directly perform response actions; instead, automation rules handle the response. Option D is wrong because watchlists are collections of data for correlation and enrichment, not for automated response.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
An automation rule
Why this is correct
Automation rules are the core mechanism within Microsoft Sentinel for orchestrating and automating incident response workflows. They are designed to automatically apply actions to incidents upon creation or update, based on specified conditions like severity, tactics, or associated entities. These rules can trigger playbooks, which are logic apps that perform complex tasks such as integrating with external systems like ServiceNow for ticketing, sending email notifications to security teams, or isolating compromised hosts. This capability makes automation rules essential for efficient SOAR operations.
- ✗
A workbook
Why it's wrong here
Microsoft Sentinel workbooks are interactive and customizable dashboards used for data visualization, exploration, and reporting. They allow security analysts to create rich visual reports from various data sources, providing insights into security posture, threat trends, and incident metrics. While workbooks are invaluable for monitoring and analysis, they are purely a presentation layer and do not have any functionality to initiate or manage automated incident response actions. Their purpose is to inform and visualize, not to automate operational tasks.
- ✗
An analytics rule
Why it's wrong here
Analytics rules in Microsoft Sentinel are designed to detect threats and generate alerts or incidents by querying ingested data for specific patterns or anomalies. They define the logic for identifying suspicious activities, such as unusual logins or malware detections, and then create a security incident when a match is found. While an analytics rule *creates* the incident that might *trigger* an automation rule, it does not directly perform automated response actions itself. Its role is solely in detection and incident creation, acting as the initial trigger point for subsequent automation.
- ✗
A watchlist
Why it's wrong here
Watchlists in Microsoft Sentinel serve as static lists of data, such as high-value assets, terminated employees, or known threat indicators, used to enrich security data and aid in threat detection. They are primarily for data correlation and lookup within analytics rules or hunting queries, allowing security analysts to identify relevant entities or activities. However, watchlists themselves do not possess any inherent capability to trigger automated response actions or orchestrate incident workflows. Their function is purely informational and correlational, not operational automation.
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
SIEM
SIEM (Security Information and Event Management) is a system that collects and analyzes log data from across an IT environment to detect and respond to security threats in real time.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.