hardMultiple Choice
SC-200 Practice Question: A SOC analyst needs to create an automated…
A SOC analyst needs to create an automated response in Microsoft Sentinel that, when a specific type of incident is created, automatically creates a ticket in ServiceNow and blocks the source IP address in Azure Firewall. The analyst already has a playbook that performs these actions. What is the correct configuration to trigger this playbook?
⚠ Common exam trap
Many exam-takers confuse automation rules (which trigger on incident lifecycle events) with scheduled playbooks or external flows, overlooking that automation rules are the native, event-driven mechanism for incident-triggered automation in Sentinel.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Attach the playbook to an automation rule that includes the condition for the target incident type.
Automation rules in Microsoft Sentinel are the correct mechanism to trigger a playbook automatically when an incident is created. By attaching the playbook to an automation rule with a condition that matches the specific incident type (e.g., based on incident title or tag), the rule executes the playbook immediately upon incident creation, fulfilling the requirement without manual intervention.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Attach the playbook to an automation rule that includes the condition for the target incident type.
Why this is correct
Automation rules are the native, event-driven mechanism in Microsoft Sentinel that invoke playbooks automatically when an incident is created or updated. By including a condition for the specific incident type, the rule triggers the playbook immediately upon a match, enabling real-time response without analyst intervention. This is the recommended and supported method for automated incident response in Sentinel.
- ✗
Configure the playbook to run on a scheduled recurrence every 5 minutes.
Why it's wrong here
A scheduled playbook runs on a fixed timer, not on incident creation, so a new incident could go unhandled for up to five minutes or longer. It would require additional custom logic to query for unprocessed incidents each cycle, which is inefficient and not an immediate, event-driven response. Automation rules are designed to fire the moment an incident matches the condition, whereas scheduled recurrence introduces unnecessary latency.
- ✗
Add the playbook to the incident's comments as a quick link.
Why it's wrong here
Adding the playbook to the incident's comments as a quick link provides only a manual hyperlink for analysts to click; it does not execute the playbook or trigger any automation. The link remains static and requires human action, whereas true automated response needs an event-driven trigger, such as an automation rule, to invoke the playbook. This approach does not reduce analyst workload or improve response time.
- ✗
Use a separate Power Automate flow with a trigger that watches for new Sentinel incidents.
Why it's wrong here
While Power Automate can be integrated with Microsoft Sentinel using a connector and a trigger that watches for new incidents, this is an external integration that duplicates the native automation rule functionality. It introduces additional complexity around authentication, permissions, and connector latency, and it is not the standard approach within Sentinel. Automation rules with playbooks are the first-class, integrated solution directly inside the Sentinel portal.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.