SC-200 Respond to security incidents Practice Question
An organization uses Microsoft Sentinel for security operations. A security engineer needs to automatically disable a compromised user account in Microsoft Entra ID when a high-severity incident is created in Sentinel. Which feature should the engineer use?
⚠ Common exam trap
SC-200 often tests the confusion between analytics rules (detection) and automation rules (response), leading candidates to select analytics rules for automated remediation tasks.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Automation rule with a playbook
To automatically disable a compromised user account in Microsoft Entra ID when a high-severity incident is created in Sentinel, the engineer should use an automation rule that triggers a playbook. Automation rules in Microsoft Sentinel allow you to define conditions (e.g., incident severity) and then invoke a playbook, which can contain the logic to call Microsoft Graph or Entra ID to disable the user. This is the standard method for automated response.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Analytics rule
Why it's wrong here
Analytics rules detect threats and generate incidents or alerts; they do not perform remediation actions such as disabling an account. Detection is tempting because it precedes response, but the required automated containment is handled by an automation rule triggered on incident creation.
- ✗
Workbook
Why it's wrong here
Workbooks render interactive reports and dashboards from query data; they cannot trigger automated actions or call Microsoft Entra ID. Visualisation is tempting when investigating incidents, but remediation requires an automation rule, which responds to incident creation.
- ✓
Automation rule with a playbook
Why this is correct
An automation rule triggers on incident creation and launches a playbook, which executes the Logic Apps workflow calling Microsoft Entra ID to disable the compromised account. This satisfies the requirement for automatic response without manual analyst intervention.
- ✗
Hunting query
Why it's wrong here
Hunting queries are run manually by analysts to explore data proactively; they neither trigger on incident creation nor execute response actions against Microsoft Entra ID. Proactive searching is tempting during investigations, but automation requires an automation rule instead.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.