Courseiva
mediumMultiple Choice

SC-200 Practice Question: A SOC analyst needs to create an automation rule…

A SOC analyst needs to create an automation rule that triggers only when an incident contains a specific custom tag (e.g., 'PII'). Which condition should the analyst use to filter incidents based on the presence of that tag?

⚠ Common exam trap

Candidates often confuse incident-level tags with alert-level properties or entity attributes, mistakenly thinking 'Alert product name' or 'Entity type' can filter by custom tags, when in fact only the 'Incident tag contains' condition directly evaluates tags assigned to the incident.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Incident tag contains

Microsoft Sentinel automation rules use the 'Incident tag contains' condition to filter incidents based on the presence of specific custom tags. When an incident is enriched with a tag like 'PII' via analytics rules or playbooks, this condition allows the automation rule to match and trigger actions only on incidents carrying that exact tag, ensuring precise targeting without affecting unrelated incidents.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Incident tag contains

    Why this is correct

    The 'Incident tag contains' condition triggers when an incident has a specific custom tag, such as 'VIP' or 'Phishing Campaign', assigned to it. This allows the automation rule to apply targeted actions, like creating a ticket or notifying a team, only for incidents that carry that business or classification label. Unlike severity or source filters, this directly evaluates the tag metadata on the incident.

  • ✗

    Incident severity

    Why it's wrong here

    The 'Incident severity' condition filters solely by the incident's assigned severity level, ranging from Informational to Critical, and does not evaluate any tags. An incident may be tagged with 'Compliance' but still have a Low severity, causing the rule to miss the tag entirely. Thus, choosing severity would not satisfy a requirement to match on a specific tag.

  • ✗

    Alert product name

    Why it's wrong here

    This condition matches on the name of the security product or provider that generated the alert, such as Microsoft Defender for Office 365 or Microsoft Sentinel itself. It is not aware of any tags that might be attached to the incident, as tags are a separate metadata layer. Using this filter would trigger on incidents from that product regardless of whether the required tag exists.

  • ✗

    Entity type

    Why it's wrong here

    The 'Entity type' condition evaluates the type of entity identified in the incident, such as Account, IP address, or Host, and does not consult incident tags. Even if an entity like an IP is present, the rule cannot determine if the incident has the desired tag. This filter is meant for entity-focused orchestration, not label-based classification.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.