SC-200 Manage a security operations environment Practice Question
A security operations center (SOC) uses Microsoft Sentinel. You need to ensure that when a high-severity incident is created, an automated email notification is sent to the on-call security engineer. Which automation option should you use?
⚠ Common exam trap
A common mix-up: candidates confuse analytics rules (which generate alerts) with automation rules (which respond to incidents), leading candidates to incorrectly select Option A instead of recognizing that playbooks are the correct automation mechanism for email notifications.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a playbook that sends an email and associate it with an automation rule that triggers on high-severity incidents.
Microsoft Sentinel uses automation rules to trigger playbooks (Azure Logic Apps) based on incident creation or update conditions. By associating a playbook that sends an email with an automation rule set to trigger on high-severity incidents, the SOC achieves fully automated, event-driven notification without manual intervention.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Set an analytics rule to run a KQL query and send email.
Why it's wrong here
Analytics rules in Microsoft Sentinel are detection mechanisms that execute KQL queries on a schedule to identify threats, and when matches occur, they generate alerts and incidents. They do not contain built-in email or notification actions—the rule's output is an incident, not a message. To send email, you would need to create a playbook (Logic App) and attach it to an automation rule that runs when the incident is created, so simply setting the analytics rule to email is not possible or sufficient.
- ✗
Create a workbook that emails the on-call engineer daily.
Why it's wrong here
Azure Workbooks are interactive dashboard templates that aggregate and visualize Sentinel data from multiple sources; they are designed for analysis and reporting, not for sending notifications. A workbook cannot be scheduled to email an engineer because it has no email provider or send action, and refreshing a workbook does not trigger external communications. Automated emailing requires an automation rule and a playbook, not a workbook.
- ✗
Configure a logic app manually triggered by the analyst.
Why it's wrong here
While logic apps can serve as playbooks in Sentinel, configuring one to be manually triggered means the analyst must execute it each time, which does not meet the requirement for an automated notification workflow. A manual trigger only fires when someone clicks the run button in the Logic Apps designer, and it does not respond to incident creation or severity automatically. For high-severity incidents to trigger an email without human intervention, the playbook must be associated with an automation rule that has the appropriate condition.
- ✓
Create a playbook that sends an email and associate it with an automation rule that triggers on high-severity incidents.
Why this is correct
This is correct because Sentinel integrates with Azure Logic Apps to create playbooks—workflows that can perform actions like sending email via the Office 365 Outlook connector. An automation rule can be configured with a condition for high-severity incidents and an action to run a playbook, which automatically executes the email-sending workflow when an incident is created. This provides the fully automated notification mechanism required, with no manual steps.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.