SC-200 Respond to security incidents Practice Question
Exhibit
Refer to the exhibit.
```json
{
"properties": {
"displayName": "Block Malicious IP",
"trigger": {
"type": "Microsoft.SecurityInsights/alertRule",
"alertRuleId": "1234"
},
"actions": [
{
"type": "Microsoft.SecurityInsights/incidentAction",
"actionType": "BlockIP",
"properties": {
"ipAddress": "@{triggerBody()?['properties']?['alertRuleId']}",
"blockDuration": "P1D"
}
}
]
}
}An analyst creates a playbook in Microsoft Sentinel to automatically block an IP address when an alert fires. However, the playbook fails to block the IP. What is the most likely cause?
⚠ Common exam trap
It's easy for candidates to assume the playbook trigger or action count is the problem, when the real issue is data extraction from the alert schema—a common oversight in automation workflows.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The IP address is being extracted from an incorrect field in the alert
The most likely cause is that the playbook is extracting the IP address from an incorrect field in the alert. In Microsoft Sentinel, playbooks use the SecurityAlert schema, where the IP address may be stored in different fields (e.g., 'RemoteIP', 'SourceIP', 'DestinationIP') depending on the alert provider. If the playbook references the wrong field, it will pass a null or incorrect value to the block action, causing the automation to fail silently or target the wrong entity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The IP address is being extracted from an incorrect field in the alert
Why this is correct
The playbook is correctly triggered but fails because it references 'alertRuleId' as the IP address. In Sentinel alert payloads, alertRuleId is merely the identifier of the analytics rule that generated the alert, not a network entity. The IP address must be extracted from the 'Entities' collection of the incident, specifically from an entity with type 'IP' (e.g., Entities.IP.address). Passing a non-IP string to a block action causes input validation failure, so the playbook cannot block the address.
- ✗
The block duration is set to one day, which is too short
Why it's wrong here
A block duration of one day does not cause a playbook failure. The duration parameter simply controls how long the IP remains on the block list after the action completes; it is validated as a valid time span. While one day might be operationally insufficient for containing a persistent threat, it does not affect whether the playbook runs successfully. The root cause of the failure is not the duration but the incorrect IP extraction.
- ✗
The playbook actions array has only one action, which is insufficient
Why it's wrong here
Having only one action in the actions array is not a problem. Microsoft Sentinel playbooks, built on Azure Logic Apps, can be as simple as a single connector action, such as an IP-blocking action, and will execute successfully as long as the inputs are valid. The playbook's effectiveness is determined by what that action does and the data it receives, not by the number of actions. Therefore, insufficient action count is not the reason for the failure.
- ✗
The playbook is using the wrong trigger type; it should be on incident creation
Why it's wrong here
The trigger type is actually correct for this alert-based playbook. Alert-triggered playbooks in Sentinel use the 'When a response to an Azure Sentinel alert is triggered' trigger, which fires immediately when an incident is created from an alert. The incident creation trigger is used for incident-centric automation, not for directly processing alert entities in the same context. Since the playbook is designed to act on individual alert data, the alert trigger is appropriate, and the mistake lies elsewhere in field extraction.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.