SC-200 Respond to security incidents Practice Question
A SOC analyst is investigating a Microsoft Sentinel incident involving a compromised service principal. The analyst needs to enrich the incident with information from an external threat intelligence platform that exposes a REST API and requires an API key. The enrichment must run automatically each time a matching incident is created and must not require manual steps. Which Microsoft Sentinel component should the analyst use to implement this enrichment?
⚠ Common exam trap
The trap here is assuming a data connector or analytics rule can call an external API; only playbooks (Logic Apps) can perform outbound API calls with secrets and write enrichment back to the incident.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A Microsoft Sentinel playbook triggered by an automation rule
Automated enrichment using an external API with an API key requires a Logic Apps-based playbook, which can securely store secrets, make HTTP calls, and write results back to the incident. Automation rules provide the trigger mechanism when an incident is created, ensuring the playbook runs without manual intervention. Analytics rules, workbooks, and data connectors serve different purposes and cannot fulfill the automated external enrichment requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A data connector for the threat intelligence platform
Why it's wrong here
Data connectors ingest data into a Microsoft Sentinel workspace, such as threat indicators into the ThreatIntelligenceIndicator table. They do not perform outbound API calls to enrich incidents, nor do they attach results to an incident automatically. While a connector could import indicators for matching, it would not call the REST API with an API key or provide incident-level enrichment as required here.
- ✗
A workbook with a custom parameter
Why it's wrong here
Workbooks are visualization and reporting canvases built on Azure Monitor workbooks. They can display data from Log Analytics and other sources, and parameters can filter views, but they do not execute API calls or enrich incidents. A workbook would only present information for a human to read, and it cannot automatically attach enrichment to an incident or run on incident creation, so it fails the automated requirement.
- ✗
A scheduled analytics rule with entity mapping
Why it's wrong here
Scheduled analytics rules generate alerts and incidents from queries, and entity mapping helps identify users, hosts, and IPs within those alerts. However, they do not natively call external REST APIs that require an API key, nor do they attach arbitrary enrichment data back to an incident. Using a scheduled rule here would not satisfy the automated external enrichment requirement and would likely require additional orchestration.
- ✓
A Microsoft Sentinel playbook triggered by an automation rule
Why this is correct
Playbooks are Logic Apps workflows that can call external REST APIs, handle API keys via secure inputs, and post results back to the incident as comments, tags, or entities. Automation rules can trigger a playbook automatically when an incident is created, matching the requirement for automatic enrichment on matching incidents. This combination provides the required no-touch, repeatable enrichment using the external threat intelligence platform.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.