SC-200 Respond to security incidents Practice Question
An organization uses Microsoft Sentinel and Microsoft Defender XDR. A critical incident is created when a user is detected as compromised. The incident severity is set to High. The SOC manager wants to ensure that all incidents with severity High or above are automatically assigned to the senior analyst tier. What should the analyst configure?
⚠ Common exam trap
SC-200 often tests the confusion between automation rules (incident-level routing/assignment) and playbooks (action orchestration) — candidates pick playbooks for simple assignment tasks that automation rules handle natively.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Define an automation rule to assign incidents based on severity.
Microsoft Sentinel automation rules are designed to trigger on incident creation and perform actions such as assigning owners, changing severity, adding tags, or running playbooks. To automatically assign all High-or-above incidents to the senior analyst tier, an automation rule with a severity condition and an 'Assign owner' action is the correct mechanism.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Set a playbook to run when an incident is created.
Why it's wrong here
A playbook triggers on incident creation but must itself evaluate severity and set owner; the native assignment mechanism is what enforces High-or-above routing without custom logic. Playbooks are tempting because they automate response actions, and would be correct for enrichment, notification or remediation steps.
- ✗
Create an analytics rule with a custom severity.
Why it's wrong here
Analytics rules generate alerts and incidents with defined severity; they do not assign ownership, so a custom severity leaves the senior tier unassigned. It is tempting because severity drives automation triggers, and would be correct if the goal were detecting a new threat rather than routing existing High incidents.
- ✓
Define an automation rule to assign incidents based on severity.
Why this is correct
Automation rules in Microsoft Sentinel trigger on incident creation and can set owner, status or severity. Configuring one with a severity condition of High or above automatically assigns matching incidents to the senior analyst tier, removing manual triage effort.
- ✗
Configure an alert tuning rule.
Why it's wrong here
Alert tuning rules suppress, merge or adjust noisy alerts before incidents form; they never assign incidents to a tier. Tuning is tempting because it reduces SOC workload, and would be correct when the problem is false-positive volume rather than ownership routing.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.