Exam objective

SC-900

Describe capabilities of Microsoft Sentinel

This objective sits in Describe capabilities of Microsoft security solutions, which carries 38% of the Security, Compliance, and Identity Fundamentals exam. The questions below are original, written from the official objective title above, and each explanation cites the Microsoft Azure page it rests on.

Objective title verbatim from the official objectives. Microsoft Azure exam page ↗

A worked example

Shown solved, with the whole explanation open: this is what every question here carries.

Describe capabilities of Microsoft security solutions

When an account is flagged for suspicious sign-ins, a team wants it disabled, a notification sent and a ticket opened without an analyst starting each step. Which SOAR concept is this?

A correlation ruleCorrelation finds relationships between events to detect a threat; it does not carry out responses.
A playbookCorrect · your answerCorrect.
A log aggregation pipelineLog aggregation gathers events into one platform; it is a SIEM input, not a response.
An incidentAn incident is the case file that groups related alerts; the automated response to it is the playbook.

Correct.

Checked against learn.microsoft.com, September 2026

Concept

Detection tells you something happened; the automation that carries out a fixed sequence of response steps is a separate idea with its own name.

Why B

The source calls a playbook a predefined sequence of automated actions triggered by a specific alert or incident type, and gives disabling the account, notifying the team, and opening a ticket as its example.

Source

A key SOAR concept is the playbook -a predefined sequence of automated actions triggered by a specific alert or incident type. For example, when a user account is flagged for suspicious sign-in activity, a playbook can automatically: Disable the account. Send a notification to the security team. Open an incident ticket in the help desk system.

Define the concepts of SIEM and SOAR, checked September 2026
#soar#playbook#scenario

Now you: practice questions

No account needed. The explanation opens when you answer.

Sample question 1 of 3

Describe capabilities of Microsoft security solutions

Microsoft Sentinel links several low-severity signals from different sources into one high-confidence incident that no single rule would have raised. Which capability does this?

Sample question 2 of 3

Describe capabilities of Microsoft security solutions

A SOC wants every ingested event compared automatically against feeds of known malicious IP addresses, domains and URLs. Which Microsoft Sentinel detection approach does this?

Sample question 3 of 3

Describe capabilities of Microsoft security solutions

A security team wants to keep years of security logs at low cost so it can build behavioral baselines and investigate persistent threats. Which part of Microsoft Sentinel is designed for this?

Full Security, Compliance, and Identity Fundamentals question bank coming

We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.

Read the sources

These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.

More objectives in Describe capabilities of Microsoft security solutions