Courseiva

SC-100 Automation rules Practice Question

Your organization uses Microsoft Sentinel for security operations. You need to ensure that all incidents are automatically assigned to the appropriate analyst team based on the type of threat. What should you configure?

⚠ Common exam trap

A common mistake is to think that playbooks are needed for incident assignment, but automation rules provide a simpler and more direct way to set incident owners based on conditions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure an automation rule to set the incident owner based on custom conditions.

The correct option is D: configure an automation rule to set the incident owner based on custom conditions. Microsoft Sentinel automation rules are designed to run on incident creation or updates and can assign an owner (analyst or team) using conditions such as the incident's title, severity, tactics, or custom details, which directly matches the requirement to route incidents by threat type. Option A is wrong because a watchlist alone does not assign incidents and would require an unnecessary logic app; watchlists are reference data, not automation triggers. Option B is wrong because analytics rules generate incidents and can add custom details or entity mappings, but they do not assign incident ownership to a team. Option C is wrong because playbooks are Logic Apps triggered by automation rules or analytics rules and are used for response actions, not as the primary mechanism for setting incident owner based on conditions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use a watchlist to map threat types to teams and trigger a logic app.

    Why it's wrong here

    Watchlists are ephemeral reference tables used to enrich or filter queries during log analytics, not a configuration mechanism to drive incident operations. While you could technically trigger a Logic App via a watchlist item, the automation rule engine is Sentinel's native, low-friction way to set an incident owner based on conditions. Relying on a watchlist for ownership assignment adds unnecessary moving parts and does not integrate with the incident pipeline in the same first-class manner.

  • ✗

    Modify the analytics rule to include a custom field for the assigned team.

    Why it's wrong here

    Analytics rules are purely detection logic: they define which raw events or alerts produce an incident, and they can add custom properties like entities or tags, but they do not control the post-detection incident lifecycle. The 'owner' field is a distinct, managed property on the incident object, not an arbitrary custom field that a query can populate. Modifying the rule to carry team information would require a secondary mechanism (e.g., an automation rule) to translate that into ownership, making it an indirect and incomplete solution.

  • ✗

    Create a playbook that assigns ownership based on incident properties.

    Why it's wrong here

    Playbooks are Logic Apps-based workflows designed for complex orchestration, such as sending approval emails, enriching data, or invoking external systems, and they can indeed update the incident owner via the API if invoked. However, for a simple, immediate owner assignment, an automation rule is the purpose-built, native action that runs directly in Sentinel without the latency, licensing, or permission overhead of a playbook. Playbooks are better suited to multi-step or conditional response where you also need to communicate with external systems, not as the primary owner-assignment mechanism.

  • ✓

    Configure an automation rule to set the incident owner based on custom conditions.

    Why this is correct

    Automation rules are the native Sentinel feature that lets you set incident properties—including owner—based on conditions like severity, tags, or rule name, and they execute automatically when an incident is created or updated. This is a built-in action with no external dependencies, so it runs reliably, quickly, and with minimal configuration, making it the correct solution. You can specify a user or group as owner, and the rule will apply that assignment when the incident matches your custom conditions.

About these practice questions

Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.