easyMultiple Choice
SC-200 Practice Question: A security operations center (SOC) uses Microsoft…
A security operations center (SOC) uses Microsoft Sentinel. The team wants to automatically assign incidents to the appropriate analyst based on the severity level of the alert. Which feature should be configured to achieve this automation?
⚠ Common exam trap
Many exam-takers confuse playbooks with automation rules, thinking playbooks are required for any automated action, but automation rules handle simple, condition-based assignments natively without needing a Logic App.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Automation rules
Automation rules in Microsoft Sentinel allow you to define conditions (such as alert severity) and corresponding actions (like assigning an incident to a specific analyst or group) without requiring custom code. This directly meets the SOC's requirement to automatically route incidents based on severity levels, as automation rules can trigger on incident creation or update and perform assignment actions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Automation rules
Why this is correct
Automation rules are Sentinel's native mechanism that runs when an incident is created or an alert is generated. For incident creation, they can automatically assign the incident to an analyst or a group based on criteria like severity, product name, or entity type. This built-in action does not require any external services, making it the primary and most efficient way to automate incident ownership and triage.
- ✗
Playbooks
Why it's wrong here
Playbooks are cloud-native workflows built on Azure Logic Apps, intended for more complex, multi-step response actions such as gathering threat intelligence, isolating a device, or sending notifications. While an automation rule can invoke a playbook, and a playbook could theoretically use the 'Update incident' API to change the owner, this is not the designed or direct assignment mechanism. Assigning incidents via playbooks would introduce latency, adds deployment and maintenance overhead, and requires building custom connectors, so it is not the appropriate tool for simple ownership routing.
- ✗
Analytics rules
Why it's wrong here
Analytics rules are responsible for detection, containing the KQL queries that match suspicious or malicious activity and the settings that determine whether a rule generates an alert or an incident. They operate at the point of detection and creation, but they do not run any post-creation automation such as assigning the incident to an analyst. Once the rule generates the incident, its responsibility ends, so assignment must be handled by a separate mechanism.
- ✗
Watchlists
Why it's wrong here
Watchlists are local reference data in Microsoft Sentinel, where SOC analysts can store structured CSV content like asset inventories, VPN usernames, or high-risk IP addresses. They are used inside analytics rules or hunting queries as lookups for enrichment and correlation, not for infrastructure actions. A watchlist has no influence on incident ownership or assignment, as it is purely data, not executable automation logic.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.