Courseiva
mediumMultiple Choice

SC-200 Practice Question: A SOC team wants to automatically run a playbook…

A SOC team wants to automatically run a playbook that retrieves threat intelligence details whenever a high-severity incident is created in Microsoft Sentinel. Which type of automation should they configure?

⚠ Common exam trap

A common mix-up: candidates confuse the incident trigger with the alert trigger; candidates often select alert trigger because they think alerts are the primary event, but incidents are the higher-level object that SOC teams triage, and the question explicitly says 'incident is created'.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Automation rule with incident trigger

Automation rules in Microsoft Sentinel can be configured with an incident trigger to automatically run playbooks when incidents are created or updated. Since the requirement is to run a playbook on high-severity incidents, an automation rule with an incident trigger allows you to filter by severity (e.g., High) and invoke the playbook without manual intervention.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Automation rule with incident trigger

    Why this is correct

    Automation rules in Microsoft Sentinel are event-driven, and the incident trigger fires when a new incident is created. This trigger automatically invokes a linked playbook, passing the incident's properties and entities so the playbook can retrieve relevant data immediately. Because no human interaction is required, this is the correct mechanism to automatically run a playbook on incident creation.

  • ✗

    Automation rule with alert trigger

    Why it's wrong here

    An alert trigger automation rule executes when a raw alert is generated by an analytics rule, before any incident is formed. The playbook would therefore only receive alert-level context, not incident-level context, and may run prematurely if the alert is later correlated into an incident. This does not satisfy the requirement to run the playbook when an incident is created, because the incident does not yet exist.

  • ✗

    Playbook with manual trigger

    Why it's wrong here

    A playbook with a manual trigger is launched on demand from the Sentinel interface, such as a button on the incident details page or a custom command. It requires an analyst to click the trigger, so it cannot automatically run when an incident is created. This defeats the SOC team's goal of unattended, automatic execution and introduces human delay into the response process.

  • ✗

    Logic app with recurrence

    Why it's wrong here

    A Logic App with a recurrence trigger runs on a fixed schedule, such as every hour, rather than in real-time response to an incident creation event. It would need to poll the Microsoft Sentinel API for new incidents and would introduce latency, and the run is not synchronized with the exact moment the incident is created. This is not the native event-driven automation pattern that incident-based playbooks use.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.