AZ-500 Practice Question: Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel
You are a security engineer for a company that uses Microsoft Sentinel. The security operations center (SOC) wants to automatically assign new incidents to the on-call analyst based on the incident's severity and product name. You need to configure this with minimal administrative effort. What should you do?
⚠ Common exam trap
The trap here is assuming that analytics rules or incident settings can automatically assign incident owners, when in fact that capability resides in automation rules.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an automation rule that triggers when an incident is created and uses conditions on severity and product name to assign the incident to a specific owner.
Automation rules in Microsoft Sentinel are the native mechanism for automatically triaging incidents. They can trigger on incident creation, evaluate conditions such as severity and product name, and perform actions like assigning an owner. This approach requires minimal configuration and directly addresses the SOC's requirement without the overhead of building a playbook.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create an automation rule that triggers when an incident is created and uses conditions on severity and product name to assign the incident to a specific owner.
Why this is correct
Automation rules in Microsoft Sentinel are designed to automatically triage incidents. They can trigger on incident creation and evaluate conditions such as severity and product name. The action 'Assign owner' allows you to set the incident owner dynamically, fulfilling the requirement with minimal effort.
- ✗
Use an analytics rule that groups related alerts into incidents and sets the owner based on severity and product name.
Why it's wrong here
Analytics rules are used to create incidents from alerts, but they do not support assigning an owner based on incident properties. The owner assignment must be done after incident creation, typically via automation rules or playbooks. Analytics rules focus on detection, not incident management actions.
- ✗
Configure a playbook that runs on incident creation and uses the 'Update incident' action to assign the incident to the on-call analyst.
Why it's wrong here
Playbooks are Logic Apps that can perform complex workflows, but they require more configuration than automation rules. While a playbook can update an incident, it does not natively support dynamic assignment based on incident properties without additional coding, making it less efficient for this scenario.
- ✗
Modify the incident settings in Microsoft Sentinel to enable automatic assignment of incidents to the on-call analyst based on severity and product name.
Why it's wrong here
Microsoft Sentinel does not have a built-in feature that automatically assigns incidents based on severity and product name. While there are incident settings for grouping and visibility, automatic owner assignment requires an automation rule or playbook. This option misrepresents the available functionality.
Go deeper
Related to this question
About these practice questions
This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.