SC-200 Manage a security operations environment Practice Question
A security analyst receives a high-severity incident in Microsoft Sentinel for a user who is suspected of lateral movement. The analyst wants to automatically run a playbook that isolates the user's machine and disables their account when such an incident is created. What is the most efficient way to achieve this?
⚠ Common exam trap
Test-takers frequently confuse analytics rules (which generate alerts) with automation rules (which respond to incidents), leading candidates to incorrectly choose option C because they think a playbook must be tied directly to the alert generation process.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an automation rule that triggers the playbook when the incident is created
Automation rules in Microsoft Sentinel are designed to trigger playbooks automatically when an incident is created, based on conditions like severity or rule name. This provides the most efficient, event-driven response without polling or manual intervention, directly addressing the requirement to isolate the machine and disable the account upon incident creation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure a Logic Apps trigger to poll for new incidents every minute
Why it's wrong here
Polling for new incidents every minute with a Logic Apps trigger is inefficient and adds latency, because it introduces a scheduled delay and requires custom HTTP calls to the Microsoft Sentinel API instead of using the native event-driven integration. Automation rules, by contrast, respond instantly to incident creation via a subscription-scoped trigger, eliminating the need for polling and providing immediate, serverless execution without additional compute costs.
- ✗
Train analysts to manually run the playbook when they see the incident
Why it's wrong here
Manual playbook execution depends on analyst availability and reaction time, so isolation and account disabling are delayed, letting lateral movement continue. Automation rules with playbook triggers are designed for this, whereas manual running suits rare, judgement-heavy incidents where automated containment would be risky.
- ✗
Create an analytics rule that runs a playbook as part of its alert generation
Why it's wrong here
An analytics rule cannot directly invoke a playbook as part of alert generation; analytics rules are designed to evaluate data and create alerts, not to orchestrate response actions. Playbooks are executed by automation rules, which listen for incident creation or update events and run the playbook as an action. While an analytics rule can alert on a detection, the playbook must be attached via an automation rule, or else you would need unsupported custom extensions to call it from the rule logic.
- ✓
Create an automation rule that triggers the playbook when the incident is created
Why this is correct
Creating an automation rule that triggers the playbook when the incident is created is the correct, documented approach in Microsoft Sentinel. Automation rules use a trigger condition (incident creation) to run a playbook automatically, and they provide a simple, event-driven integration with Logic Apps. This ensures the playbook executes immediately and consistently for every matching incident, without the need for manual intervention or custom polling logic.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.