mediumMultiple Choice
SC-200 Practice Question: Uses Microsoft Sentinel with the Microsoft…
An organization uses Microsoft Sentinel with the Microsoft Defender for Cloud connector enabled. A security analyst receives an alert from Defender for Cloud about a potential brute-force attack on an Azure VM. The analyst wants to automatically create an incident in Sentinel and trigger a playbook that blocks the attacker's IP using a firewall. Which type of Sentinel automation rule should the analyst configure?
⚠ Common exam trap
A common mix-up: candidates confuse 'analytics rule automation' with 'incident automation rule'—candidates often think the automation must be tied to the rule that generated the alert, but Sentinel separates alert generation (analytics rules) from incident-level actions (incident automation rules).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Incident automation rule
Incident automation rules in Microsoft Sentinel allow you to automatically trigger a playbook when an incident is created or updated. Since the Defender for Cloud alert generates an incident in Sentinel, an incident automation rule can be configured to run a playbook that blocks the attacker's IP via a firewall, meeting the requirement without needing to modify the analytics rule itself.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Analytics rule automation
Why it's wrong here
Analytics rules are scheduled query rules that generate alerts and incidents based on log data. While you can attach automation rules to analytics rules for alert-triggered responses, this is distinct from incident automation. Analytics rule automation does not natively provide incident-creation-time playbook triggers; that capability belongs to incident automation rules.
- ✓
Incident automation rule
Why this is correct
Incident automation rules are the central mechanism in Microsoft Sentinel for defining automated responses at the incident level. They execute when an incident is created or updated, and can trigger playbooks to perform actions such as blocking an IP address, assigning an owner, or adding tags. They support conditions, ordering, and multiple actions, making them essential for SOAR workflows.
- ✗
Playbook trigger
Why it's wrong here
A playbook trigger is not a type of automation rule; it refers to the Logic Apps event that starts a playbook, such as an HTTP request received from Sentinel. Playbooks themselves are triggered by automation rules or manually from an incident, and the trigger type is configured inside the Logic App designer. Therefore, calling it an automation rule category is incorrect.
- ✗
Custom log ingestion
Why it's wrong here
Custom log ingestion is a data collection method that allows you to bring external data into Sentinel via Log Analytics APIs or connectors, storing it in custom tables. It is used for data enrichment and visibility, not for automating incident responses. This option is unrelated to playbook triggering or incident automation.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.