Courseiva
mediumMultiple Select

SC-200 Practice Question: A SOC analyst is configuring a Microsoft Sentinel…

A SOC analyst is configuring a Microsoft Sentinel automation rule to trigger a playbook when an incident is created. The playbook should only run if the incident severity is 'High' and the incident title contains 'Phishing'. Which two conditions should the analyst add to the automation rule? (Select all that apply.) (Choose 2.)

⚠ Common exam trap

The trap here is that candidates may mistakenly add 'Incident status is New' thinking the playbook should only run on newly created incidents, but the automation rule already triggers 'when an incident is created', making the status condition redundant and incorrect for this specific requirement.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Incident severity equals High

The automation rule condition 'Incident severity equals High' directly matches the requirement that the playbook should only trigger for incidents with a severity of 'High'. In Microsoft Sentinel, automation rules evaluate conditions against incident properties, and severity is a standard field that can be filtered using the 'equals' operator. This ensures the playbook is not invoked for lower-severity incidents.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Incident severity equals High

    Why this is correct

    The condition 'Incident severity equals High' directly implements the SOC's stated requirement to trigger the automation runbook for high-severity incidents. In Microsoft Sentinel, severity is an incident property set during analytics rule detection, and this condition uses the 'equals' operator to match only incidents with the exact severity value 'High'. This ensures the automation workflow engages precisely when the security impact is most significant, without introducing extraneous restrictions.

  • ✓

    Incident title contains Phishing

    Why this is correct

    The condition 'Incident title contains Phishing' ensures the automation is specifically scoped to phishing-related incidents, as indicated by a substring match against the incident title. In Sentinel, incident titles are generated from the alert rule's title or description, so containing the term 'Phishing' is a reliable filter for campaigns or payloads that explicitly name the attack type. This condition complements the severity filter by narrowing the automation to relevant threat categories, but it is not a substitute for the severity condition because phishing can occur across multiple severities.

  • ✗

    Incident status is New

    Why it's wrong here

    The condition 'Incident status is New' is invalid as a meaningful automation trigger because the rule executes on incident creation, and by definition, incidents are created with a status of 'New'. Therefore, this condition is always true at the time the automation runs, making it a redundant filter that adds no value. It does not align with any stated requirement, and unlike severity or title, it does not help discriminate between incidents that need automation and those that do not.

  • ✗

    Incident owner is Unassigned

    Why it's wrong here

    The condition 'Incident owner is Unassigned' is an unnecessary restriction because the requirement does not mention ownership, and in a fresh incident, the owner is typically unassigned by default. Adding this condition could prevent the automation from running on incidents that have been manually assigned before the automation rule triggers, or it could introduce a race condition if ownership changes during processing. Since the automation is intended to respond to incident properties like severity and title, owner status is irrelevant and would degrade reliability.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.