Courseiva

SC-200 Respond to security incidents Practice Question

A SOC analyst is investigating a Microsoft Sentinel incident involving a compromised service principal. The analyst needs to enrich the incident with information from an external threat intelligence platform that exposes a REST API and requires an API key. The enrichment must run automatically each time a matching incident is created and must not require manual steps. Which Microsoft Sentinel component should the analyst use to implement this enrichment?

⚠ Common exam trap

The trap here is assuming a data connector or analytics rule can call an external API; only playbooks (Logic Apps) can perform outbound API calls with secrets and write enrichment back to the incident.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A Microsoft Sentinel playbook triggered by an automation rule

Automated enrichment using an external API with an API key requires a Logic Apps-based playbook, which can securely store secrets, make HTTP calls, and write results back to the incident. Automation rules provide the trigger mechanism when an incident is created, ensuring the playbook runs without manual intervention. Analytics rules, workbooks, and data connectors serve different purposes and cannot fulfill the automated external enrichment requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A data connector for the threat intelligence platform

    Why it's wrong here

    Data connectors ingest data into a Microsoft Sentinel workspace, such as threat indicators into the ThreatIntelligenceIndicator table. They do not perform outbound API calls to enrich incidents, nor do they attach results to an incident automatically. While a connector could import indicators for matching, it would not call the REST API with an API key or provide incident-level enrichment as required here.

  • ✗

    A workbook with a custom parameter

    Why it's wrong here

    Workbooks are visualization and reporting canvases built on Azure Monitor workbooks. They can display data from Log Analytics and other sources, and parameters can filter views, but they do not execute API calls or enrich incidents. A workbook would only present information for a human to read, and it cannot automatically attach enrichment to an incident or run on incident creation, so it fails the automated requirement.

  • ✗

    A scheduled analytics rule with entity mapping

    Why it's wrong here

    Scheduled analytics rules generate alerts and incidents from queries, and entity mapping helps identify users, hosts, and IPs within those alerts. However, they do not natively call external REST APIs that require an API key, nor do they attach arbitrary enrichment data back to an incident. Using a scheduled rule here would not satisfy the automated external enrichment requirement and would likely require additional orchestration.

  • ✓

    A Microsoft Sentinel playbook triggered by an automation rule

    Why this is correct

    Playbooks are Logic Apps workflows that can call external REST APIs, handle API keys via secure inputs, and post results back to the incident as comments, tags, or entities. Automation rules can trigger a playbook automatically when an incident is created, matching the requirement for automatic enrichment on matching incidents. This combination provides the required no-touch, repeatable enrichment using the external threat intelligence platform.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.