Courseiva
Manage identity and access →mediumMultiple Choice

AZ-500 Manage identity and access Practice Question

A team wants Sentinel incidents to automatically assign to the Tier 2 queue when severity is High and the product name is Microsoft Defender for Endpoint. What should they configure?

⚠ Common exam trap

Many exam-takers confuse watchlists or workbooks with operational automation, thinking they can be used for real-time incident routing, when in fact they are designed for data enrichment and visualization, not for triggering actions on incidents.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

An automation rule that updates owner/status based on conditions

Automation rules in Microsoft Sentinel allow you to automatically assign incidents to specific owners or queues based on conditions like severity and product name. By configuring an automation rule with a condition that triggers when severity equals 'High' and the product name is 'Microsoft Defender for Endpoint', you can set the incident owner to a specific user or group (e.g., Tier 2 queue) and optionally update the status. This directly meets the requirement without manual intervention.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A workbook with a dropdown filter

    Why it's wrong here

    A workbook is a read-only interactive report that visualizes Sentinel data, and although a dropdown filter can slice incidents by owner or assigned analyst, the workbook itself has no write path to alter incident properties. It might help a SOC manager manually identify unassigned incidents, but it cannot set the owner or change the incident status as an automated action. Therefore, it fails the core requirement of automatically assigning incidents.

  • ✗

    A watchlist containing Tier 2 users only

    Why it's wrong here

    A watchlist serves as a reusable source of reference data for KQL queries, alert enrichment, or detection logic, but merely containing Tier 2 user account names does not trigger any incident update. To assign an incident to a Tier 2 analyst, Sentinel would need an automation rule or playbook to read the watchlist and execute an incident action; the watchlist has no built-in mechanism to modify incidents. Thus it is passive data, not an active assignment control.

  • ✓

    An automation rule that updates owner/status based on conditions

    Why this is correct

    An automation rule in Microsoft Sentinel runs when an incident is created or updated and can evaluate conditions such as severity, service, or entity prior to executing actions. Its actions include setting the incident's owner (using a user or group name) and updating its status to Active, which directly satisfies the team's requirement to automatically assign incidents. Rules can also be ordered to ensure assignment happens before other processing, and they provide a consistent, auditable method for ownership.

  • ✗

    A data retention policy

    Why it's wrong here

    A data retention policy defines how long log data is preserved in the Log Analytics workspace, for example moving old incidents to a hot/cold tier or deleting it after a specified period. It controls the lifecycle of the raw events and Sentinel tables, but it has no effect on the operational state of an incident, such as its owner or status. Hence, it is completely unrelated to the automation of incident assignment.

About these practice questions

Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.