mediumMultiple Choice
SC-200 Practice Question: A SOC team wants to automate response to…
A SOC team wants to automate response to incidents detected by Microsoft Sentinel. When a new incident is created with severity "High" and contains a specific tag "malware", they want to run a playbook that isolates the affected device. What is the correct way to configure this automation?
⚠ Common exam trap
Many candidates think a custom analytics rule or a direct Logic App trigger is equivalent to an automation rule, but Microsoft Sentinel's automation rules are the intended and most efficient way to conditionally invoke playbooks based on incident properties like severity and tags.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an automation rule that triggers on "When incident is created" and set conditions for severity equals High and tag contains "malware", then set a playbook action.
Automation rules in Microsoft Sentinel are specifically designed to trigger playbooks based on incident creation events and conditions like severity and tag. By setting the trigger to 'When incident is created' and conditions for severity equals 'High' and tag contains 'malware', the rule will invoke the playbook to isolate the affected device automatically, without manual intervention.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create an automation rule that triggers on "When incident is created" and set conditions for severity equals High and tag contains "malware", then set a playbook action.
Why this is correct
This is the correct approach because Microsoft Sentinel automation rules are the native, first-class mechanism for responding to incidents. By triggering on 'When incident is created' and setting conditions that check for severity equals High and tag contains 'malware', the rule will evaluate every new incident and conditionally run the chosen playbook. This keeps response logic centralized in Sentinel, is easy to audit via the automation rule list, and does not require custom code or external integrations.
- ✗
Create a custom analytics rule that runs the playbook directly when triggered.
Why it's wrong here
Analytics rules are designed solely to generate alerts or incidents from data queries; they do not contain a native action to execute playbooks. Although you can attach an automated response to an analytics rule in the UI, that automation is still implemented through an underlying automation rule, not by the analytics rule itself. Therefore, writing the playbook invocation directly into the analytics rule definition would be an unsupported and fragile pattern that mixes detection with response, making it harder to manage and troubleshoot.
- ✗
Configure a logic app with a trigger on "When a Microsoft Sentinel incident is created" and use conditions inside the logic app.
Why it's wrong here
While a Logic App can be triggered directly from Sentinel incident creation using the 'When a Microsoft Sentinel incident is created' connector, this approach bypasses the automation rule layer entirely. You would have to manually recreate the same condition logic (severity/tag) inside the Logic App, handle permissions and connector setup yourself, and you lose the centralized visibility, ordering, and support that automation rules provide. For maintainability and to avoid reinventing Sentinel's native response pipeline, the condition should be expressed in an automation rule, with the Logic App invoked only via the rule's playbook action.
- ✗
Use the Microsoft Sentinel API to create a webhook that triggers the playbook.
Why it's wrong here
Using the Microsoft Sentinel API to create a webhook that triggers a playbook is an external, custom development pattern. It requires building and hosting a service that listens for webhooks, authenticating to the API, and maintaining that infrastructure, instead of using the built-in automation rule action. This is not the standard Microsoft-documented approach for incident-triggered playbooks and would not automatically integrate with incident context or automation rule evaluation, making it both less secure and less maintainable.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
3 more ways this is tested on SC-200
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A SOC team wants to automatically run a playbook that retrieves threat intelligence details whenever a high-severity incident is created in Microsoft Sentinel. Which type of automation should they configure?
medium- ✓ A.Automation rule with incident trigger
- B.Automation rule with alert trigger
- C.Playbook with manual trigger
- D.Logic app with recurrence
Why A: Automation rules in Microsoft Sentinel can be configured with an incident trigger to automatically run playbooks when incidents are created or updated. Since the requirement is to run a playbook on high-severity incidents, an automation rule with an incident trigger allows you to filter by severity (e.g., High) and invoke the playbook without manual intervention.
Variation 2. A security operations center (SOC) uses Microsoft Sentinel. The team wants to automatically assign incidents to the appropriate analyst based on the severity level of the alert. Which feature should be configured to achieve this automation?
easy- ✓ A.Automation rules
- B.Playbooks
- C.Analytics rules
- D.Watchlists
Why A: Automation rules in Microsoft Sentinel allow you to define conditions (such as alert severity) and corresponding actions (like assigning an incident to a specific analyst or group) without requiring custom code. This directly meets the SOC's requirement to automatically route incidents based on severity levels, as automation rules can trigger on incident creation or update and perform assignment actions.
Variation 3. An organization uses Microsoft Sentinel with the Microsoft Defender for Cloud connector enabled. A security analyst receives an alert from Defender for Cloud about a potential brute-force attack on an Azure VM. The analyst wants to automatically create an incident in Sentinel and trigger a playbook that blocks the attacker's IP using a firewall. Which type of Sentinel automation rule should the analyst configure?
medium- A.Analytics rule automation
- ✓ B.Incident automation rule
- C.Playbook trigger
- D.Custom log ingestion
Why B: Incident automation rules in Microsoft Sentinel allow you to automatically trigger a playbook when an incident is created or updated. Since the Defender for Cloud alert generates an incident in Sentinel, an incident automation rule can be configured to run a playbook that blocks the attacker's IP via a firewall, meeting the requirement without needing to modify the analytics rule itself.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.