Courseiva
Manage identity and accessmediumMultiple ChoiceObjective-mapped

AZ-500 Manage identity and access Practice Question

A security operations team uses Microsoft Sentinel. They want to automatically assign incidents to different tiers of analysts based on severity when incidents are created. Which feature should they configure?

⚠ Common exam trap

A common mix-up: candidates confuse automation rules with playbooks, assuming playbooks are required for any automated action, but automation rules are the correct feature for simple, rule-based incident assignment without the overhead of a full Logic App workflow.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Automation rules

Automation rules in Microsoft Sentinel allow you to automatically assign incidents to specific analysts or teams based on criteria such as severity. When an incident is created, the automation rule triggers and can set the owner (assignee) to a predefined user or group, enabling tiered assignment without manual intervention.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Fusion - Advanced Multistage Attack Detection

    Why it's wrong here

    Fusion - Advanced Multistage Attack Detection is an analytics-based detection engine in Microsoft Sentinel that uses ML models to correlate multiple low-severity alerts across different products into a single high-fidelity incident representing a multistage attack chain. It is designed to reduce alert fatigue by surfacing complex attack narratives, but it has no capabilities for incident management tasks such as assignment, prioritization, or escalation. Because the question requires automatic assignment of incidents based on severity, Fusion is not the correct tool—it only generates the incident, it does not route or assign it.

  • Analytics rules with scheduled queries

    Why it's wrong here

    Analytics rules with scheduled queries are the core mechanism in Sentinel for turning raw log data into alerts or incidents by running KQL queries on a schedule (e.g., every 15 minutes) and applying alert grouping and threshold settings. They determine when an incident is created and can set a severity based on query results, but the rules stop at creation—they do not perform post-creation actions like assigning the incident to a specific analyst or team. To automatically assign an incident after it is generated, you must use automation rules or playbooks triggered by those automation rules. Scheduled analytics rules are a prerequisite for incident generation, not a tool for incident routing or assignment.

  • Automation rules

    Why this is correct

    Automation rules allow you to automatically trigger actions like assigning an incident to a specific user or team, changing severity, adding tags, or running a playbook. This is the correct feature to automatically assign incidents based on severity.

  • Playbooks

    Why it's wrong here

    Playbooks are workflows that can be triggered manually or by automation rules. They are used for automated response actions but are not the primary mechanism for assignment of incidents; automation rules handle the initial automated actions.

About these practice questions

Courseiva writes every AZ-500 question from scratch — 194 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.