mediumMultiple Select
SC-200 Practice Question: A SOC analyst is configuring a Microsoft Sentinel…
A SOC analyst is configuring a Microsoft Sentinel automation rule to trigger a playbook when an incident is created. The playbook should only run if the incident severity is 'High' and the incident title contains 'Phishing'. Which two conditions should the analyst add to the automation rule? (Select all that apply.) (Choose 2.)
⚠ Common exam trap
The trap here is that candidates may mistakenly add 'Incident status is New' thinking the playbook should only run on newly created incidents, but the automation rule already triggers 'when an incident is created', making the status condition redundant and incorrect for this specific requirement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Incident severity equals High
The automation rule condition 'Incident severity equals High' directly matches the requirement that the playbook should only trigger for incidents with a severity of 'High'. In Microsoft Sentinel, automation rules evaluate conditions against incident properties, and severity is a standard field that can be filtered using the 'equals' operator. This ensures the playbook is not invoked for lower-severity incidents.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Incident severity equals High
Why this is correct
The condition 'Incident severity equals High' directly implements the SOC's stated requirement to trigger the automation runbook for high-severity incidents. In Microsoft Sentinel, severity is an incident property set during analytics rule detection, and this condition uses the 'equals' operator to match only incidents with the exact severity value 'High'. This ensures the automation workflow engages precisely when the security impact is most significant, without introducing extraneous restrictions.
- ✓
Incident title contains Phishing
Why this is correct
The condition 'Incident title contains Phishing' ensures the automation is specifically scoped to phishing-related incidents, as indicated by a substring match against the incident title. In Sentinel, incident titles are generated from the alert rule's title or description, so containing the term 'Phishing' is a reliable filter for campaigns or payloads that explicitly name the attack type. This condition complements the severity filter by narrowing the automation to relevant threat categories, but it is not a substitute for the severity condition because phishing can occur across multiple severities.
- ✗
Incident status is New
Why it's wrong here
The condition 'Incident status is New' is invalid as a meaningful automation trigger because the rule executes on incident creation, and by definition, incidents are created with a status of 'New'. Therefore, this condition is always true at the time the automation runs, making it a redundant filter that adds no value. It does not align with any stated requirement, and unlike severity or title, it does not help discriminate between incidents that need automation and those that do not.
- ✗
Incident owner is Unassigned
Why it's wrong here
The condition 'Incident owner is Unassigned' is an unnecessary restriction because the requirement does not mention ownership, and in a fresh incident, the owner is typically unassigned by default. Adding this condition could prevent the automation from running on incidents that have been manually assigned before the automation rule triggers, or it could introduce a race condition if ownership changes during processing. Since the automation is intended to respond to incident properties like severity and title, owner status is irrelevant and would degrade reliability.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.