SC-200 Manage a security operations environment • Set 8
SC-200 Manage a security operations environment Practice Test 8 — 15 questions with explanations. Free, no signup.
Your company uses Microsoft Sentinel and has connected Microsoft 365 Defender. You have configured an automation rule that, when an incident is created with a high severity, triggers a playbook that sends an email to the SOC manager and creates a ticket in ServiceNow. Recently, the automation rule stopped triggering the playbook. You check the automation rule and see it is enabled. You also check the playbook and see it is enabled. However, the playbook's run history shows no new runs for the last 24 hours, even though high-severity incidents have been created. You verify that the incidents are indeed high severity and that the automation rule's conditions match. What is the most likely cause?
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.