AZ-500 Manage identity and access Practice Question
A security operations team uses Microsoft Sentinel. They have created a playbook that sends an email notification to the security team when a high-severity incident is created by a specific analytics rule named 'CriticalRDPAccess'. They want the playbook to trigger automatically only when the incident has severity 'High' AND the incident was created by the rule named 'CriticalRDPAccess'. Which automation rule configuration should they use?
⚠ Common exam trap
It's easy for candidates to confuse 'contains' with 'equals' for rule name matching, or incorrectly use OR instead of AND, leading to unintended playbook triggers for similar rule names or unrelated high-severity incidents.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Condition: Incident severity equals High; AND Incident rule name equals 'CriticalRDPAccess'. Action: Run playbook.
The automation rule must use the AND operator to require both conditions—incident severity equals 'High' AND incident rule name equals 'CriticalRDPAccess'—to trigger the playbook. This ensures the playbook runs only when both criteria are met, matching the requirement exactly. Using 'contains' instead of 'equals' (as in Option A) would incorrectly match rules with 'CriticalRDPAccess' as a substring, potentially triggering on unintended rules.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Condition: Incident severity equals High; AND Incident rule name contains 'CriticalRDPAccess'. Action: Run playbook.
Why it's wrong here
Using the `contains` operator for the incident rule name makes the condition a partial substring match rather than an exact identity comparison. Consequently, any analytics rule whose name includes 'CriticalRDPAccess'—such as 'EmergencyCriticalRDPAccess' or 'CriticalRDPAccess_Test'—would also satisfy the condition and unnecessarily invoke the playbook. Exact match via `equals` is mandatory for precision so that only the intended rule triggers the automated response.
- ✗
Condition: Incident severity equals High; OR Incident rule name equals 'CriticalRDPAccess'. Action: Run playbook.
Why it's wrong here
The `OR` operator creates a disjunctive condition, meaning the playbook will run if either the severity is High or the rule name exactly equals 'CriticalRDPAccess'. As a result, a High-severity incident from any unrelated analytics rule would launch the playbook, and equally a medium-severity incident from the CriticalRDPAccess rule would also trigger it. Since the requirement is that both properties must hold in the same incident, the `AND` operator is mandatory to enforce the correct behavioral scope.
- ✓
Condition: Incident severity equals High; AND Incident rule name equals 'CriticalRDPAccess'. Action: Run playbook.
Why this is correct
This condition is correct because it uses `AND` to combine two precise constraints: the incident severity must be literally 'High', and the rule name must exactly equal 'CriticalRDPAccess' using the `equals` operator. This ensures that only High severity incidents generated by the specific analytics rule named CriticalRDPAccess will run the playbook, eliminating false positives from similarly named rules and other severity levels. The use of exact match is aligned with the Microsoft Sentinel documentation for automation rules.
- ✗
Condition: Incident severity in ['High', 'Critical']; AND Incident rule name equals 'CriticalRDPAccess'. Action: Run playbook.
Why it's wrong here
Microsoft Sentinel incident severities are limited to Informational, Low, Medium, and High—there is no 'Critical' severity tier. Including 'Critical' in the list means the condition will never evaluate to true for that value, but more importantly the `in` operator with a list containing an invalid value does not provide any benefit over a simple `equals 'High'`. To correctly restrict automation, the condition should use `equals 'High'` without referencing nonexistent severity levels, avoiding potential confusion and ensuring the playbook triggers as intended.
Go deeper
Related to this question
About these practice questions
One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.