Courseiva

SC-200 Manage a security operations environment Practice Question

A security analyst receives a high-severity incident in Microsoft Sentinel for a user who is suspected of lateral movement. The analyst wants to automatically run a playbook that isolates the user's machine and disables their account when such an incident is created. What is the most efficient way to achieve this?

⚠ Common exam trap

Test-takers frequently confuse analytics rules (which generate alerts) with automation rules (which respond to incidents), leading candidates to incorrectly choose option C because they think a playbook must be tied directly to the alert generation process.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create an automation rule that triggers the playbook when the incident is created

Automation rules in Microsoft Sentinel are designed to trigger playbooks automatically when an incident is created, based on conditions like severity or rule name. This provides the most efficient, event-driven response without polling or manual intervention, directly addressing the requirement to isolate the machine and disable the account upon incident creation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure a Logic Apps trigger to poll for new incidents every minute

    Why it's wrong here

    Polling for new incidents every minute with a Logic Apps trigger is inefficient and adds latency, because it introduces a scheduled delay and requires custom HTTP calls to the Microsoft Sentinel API instead of using the native event-driven integration. Automation rules, by contrast, respond instantly to incident creation via a subscription-scoped trigger, eliminating the need for polling and providing immediate, serverless execution without additional compute costs.

  • ✗

    Train analysts to manually run the playbook when they see the incident

    Why it's wrong here

    Manual playbook execution depends on analyst availability and reaction time, so isolation and account disabling are delayed, letting lateral movement continue. Automation rules with playbook triggers are designed for this, whereas manual running suits rare, judgement-heavy incidents where automated containment would be risky.

  • ✗

    Create an analytics rule that runs a playbook as part of its alert generation

    Why it's wrong here

    An analytics rule cannot directly invoke a playbook as part of alert generation; analytics rules are designed to evaluate data and create alerts, not to orchestrate response actions. Playbooks are executed by automation rules, which listen for incident creation or update events and run the playbook as an action. While an analytics rule can alert on a detection, the playbook must be attached via an automation rule, or else you would need unsupported custom extensions to call it from the rule logic.

  • ✓

    Create an automation rule that triggers the playbook when the incident is created

    Why this is correct

    Creating an automation rule that triggers the playbook when the incident is created is the correct, documented approach in Microsoft Sentinel. Automation rules use a trigger condition (incident creation) to run a playbook automatically, and they provide a simple, event-driven integration with Logic Apps. This ensures the playbook executes immediately and consistently for every matching incident, without the need for manual intervention or custom polling logic.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.