AZ-500 Manage identity and access Practice Question
A security operations team uses Microsoft Sentinel. They want to automatically assign incidents to different tiers of analysts based on severity when incidents are created. Which feature should they configure?
⚠ Common exam trap
A common mix-up: candidates confuse automation rules with playbooks, assuming playbooks are required for any automated action, but automation rules are the correct feature for simple, rule-based incident assignment without the overhead of a full Logic App workflow.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Automation rules
Automation rules in Microsoft Sentinel allow you to automatically assign incidents to specific analysts or teams based on criteria such as severity. When an incident is created, the automation rule triggers and can set the owner (assignee) to a predefined user or group, enabling tiered assignment without manual intervention.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Fusion - Advanced Multistage Attack Detection
Why it's wrong here
Fusion - Advanced Multistage Attack Detection is an analytics-based detection engine in Microsoft Sentinel that uses ML models to correlate multiple low-severity alerts across different products into a single high-fidelity incident representing a multistage attack chain. It is designed to reduce alert fatigue by surfacing complex attack narratives, but it has no capabilities for incident management tasks such as assignment, prioritization, or escalation. Because the question requires automatic assignment of incidents based on severity, Fusion is not the correct tool—it only generates the incident, it does not route or assign it.
- ✗
Analytics rules with scheduled queries
Why it's wrong here
Analytics rules with scheduled queries are the core mechanism in Sentinel for turning raw log data into alerts or incidents by running KQL queries on a schedule (e.g., every 15 minutes) and applying alert grouping and threshold settings. They determine when an incident is created and can set a severity based on query results, but the rules stop at creation—they do not perform post-creation actions like assigning the incident to a specific analyst or team. To automatically assign an incident after it is generated, you must use automation rules or playbooks triggered by those automation rules. Scheduled analytics rules are a prerequisite for incident generation, not a tool for incident routing or assignment.
- ✓
Automation rules
Why this is correct
Automation rules allow you to automatically trigger actions like assigning an incident to a specific user or team, changing severity, adding tags, or running a playbook. This is the correct feature to automatically assign incidents based on severity.
- ✗
Playbooks
Why it's wrong here
Playbooks are workflows that can be triggered manually or by automation rules. They are used for automated response actions but are not the primary mechanism for assignment of incidents; automation rules handle the initial automated actions.
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-500 question from scratch — 194 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.