SC-100 Practice Question: Design security operations, identity, and compliance capabilities
Your organization uses Microsoft Sentinel for security operations. You need to ensure that all incidents related to a specific critical asset are automatically assigned to the senior SOC analyst. The assignment should occur as soon as the incident is created. What should you configure?
⚠ Common exam trap
The trap here is that candidates often over-engineer the solution by selecting a playbook (Option C) for a task that can be handled natively by automation rules, failing to recognize that automation rules can directly modify incident properties without needing a playbook.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an automation rule that sets the incident owner to the senior SOC analyst.
Automation rules in Microsoft Sentinel can directly set the incident owner upon creation without requiring a playbook. This is the simplest and most efficient method for immediate assignment, as automation rules run automatically when an incident is created and can modify incident properties like owner.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Modify the analytics rule to include a custom details field for owner.
Why it's wrong here
Adding a custom details field for 'owner' to the analytics rule only enriches the alert's metadata with an additional key-value pair; it does not influence who owns the resulting incident. When an alert is created, analytics rules do not set incident ownership, which is instead determined by an automation rule's 'Set owner' action or by manual triage. Thus, the custom field would merely appear in the incident for informational purposes, not assign responsibility.
- ✓
Create an automation rule that sets the incident owner to the senior SOC analyst.
Why this is correct
An automation rule is the native, direct mechanism for assigning incident ownership at creation time. You define a trigger condition (e.g., all incidents or specific severity) and add an action to set the owner to the senior SOC analyst; the rule runs automatically the moment an incident is created, ensuring immediate accountability without human intervention. This is the simplest and most scalable approach for a one-step assignment.
- ✗
Create a playbook and trigger it from an automation rule.
Why it's wrong here
While a playbook invoked from an automation rule could technically call the update-incident API to assign an owner, it introduces unnecessary latency, cost, and dependency on Logic Apps connectivity. Automation rules already provide a first-class 'Set owner' action that requires no external orchestration, so using a playbook for simple assignment is over-engineering. Playbooks should be reserved for multi-step workflows that integrate with external systems or require conditional logic beyond native actions.
- ✗
Configure a workbook to display incidents and manually assign them.
Why it's wrong here
Workbooks are Azure Monitor-based interactive dashboards designed for visual analytics and reporting, not for performing operational actions such as assigning incidents. They render data from stored queries and have no native ability to trigger changes to Microsoft Sentinel incident properties. Manual assignment must be done through the Incidents pane, or automated via automation rules; a workbook cannot serve as an assignment interface.
Go deeper
Related to this question
About these practice questions
This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SC-100
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Your organization uses Microsoft Sentinel for security operations. You need to ensure that all incidents are automatically assigned to the appropriate analyst team based on the type of threat. What should you configure?
easy- A.Use a watchlist to map threat types to teams and trigger a logic app.
- B.Modify the analytics rule to include a custom field for the assigned team.
- C.Create a playbook that assigns ownership based on incident properties.
- ✓ D.Configure an automation rule to set the incident owner based on custom conditions.
Why D: The correct option is D: configure an automation rule to set the incident owner based on custom conditions. Microsoft Sentinel automation rules are designed to run on incident creation or updates and can assign an owner (analyst or team) using conditions such as the incident's title, severity, tactics, or custom details, which directly matches the requirement to route incidents by threat type. Option A is wrong because a watchlist alone does not assign incidents and would require an unnecessary logic app; watchlists are reference data, not automation triggers. Option B is wrong because analytics rules generate incidents and can add custom details or entity mappings, but they do not assign incident ownership to a team. Option C is wrong because playbooks are Logic Apps triggered by automation rules or analytics rules and are used for response actions, not as the primary mechanism for setting incident owner based on conditions.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.