Courseiva
hardMultiple Select

SC-200 Practice Question: A SOC analyst in Microsoft Sentinel needs to…

A SOC analyst in Microsoft Sentinel needs to create an automation rule that triggers a playbook when a new incident is created and the incident severity is 'High'. Additionally, the playbook should only run if the incident is not already assigned to an analyst. Which two conditions must the analyst include in the automation rule? (Select all that apply.) (Choose 2.)

⚠ Common exam trap

Many exam-takers confuse the 'Status' condition with the 'Assigned to' condition, thinking a 'New' status is necessary, but the automation rule triggers on incident creation by default, and the 'Assigned to' null check is the precise way to enforce the unassigned requirement.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Condition: 'Severity' equals 'High'

The automation rule must trigger only when the incident severity is 'High'. In Microsoft Sentinel, automation rules evaluate conditions against incident properties, and the 'Severity' condition filters incidents by their assigned severity level. This ensures the playbook runs exclusively for high-severity incidents, aligning with the SOC's requirement to prioritize critical alerts.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Condition: 'Severity' equals 'High'

    Why this is correct

    In Microsoft Sentinel, the Severity field on an incident reflects the impact level set by the analytics rule that generated it. Filtering on 'High' is meaningful because it limits the automation to incidents requiring urgent attention, which aligns with a SOC workflow that prioritizes critical alerts. This condition, however, does not address ownership, so it is a correct but partial filter for the playbook's purpose.

  • ✓

    Condition: 'Assigned to' equals 'null'

    Why this is correct

    The 'Assigned to' property, also called the owner, is null when no analyst has taken responsibility for the incident. By requiring this condition, the playbook only runs on unassigned incidents, which is the intended state for automatic assignment or escalation logic. This directly satisfies the requirement to avoid interfering with incidents already being handled.

  • ✗

    Condition: 'Status' equals 'New'

    Why it's wrong here

    An incident's Status field and Assigned to field are independent dimensions—an incident can be 'New' while still having an assigned owner, or 'In Progress' while unassigned. Since the playbook aims to process unassigned incidents, checking only Status equals 'New' would not exclude already-assigned New incidents, and it would also miss unassigned incidents that are not in New status. Thus, this condition does not reliably match the intended scope.

  • ✗

    Condition: 'Provider' contains 'Microsoft Sentinel'

    Why it's wrong here

    In Microsoft Sentinel, every incident generated by an analytics rule automatically gets 'Microsoft Sentinel' as its Provider value, because the provider is recorded as the rule component that created the incident. As a result, a condition checking Provider contains 'Microsoft Sentinel' is always true for essentially all incidents in the workspace, providing no filtering at all. It fails to restrict by severity or assignment, so it cannot be the main condition for a playbook that targets specific incidents.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.