SC-200 Respond to security incidents Practice Question
During a ransomware incident, Microsoft Sentinel generated an incident with high severity. The incident includes alerts from Microsoft Defender for Endpoint, Microsoft Defender for Office 365, and Microsoft Entra ID. Your team needs to automate the containment process. What is the best approach to automatically isolate affected devices and disable compromised accounts?
⚠ Common exam trap
SC-200 often tests the difference between detection (creating incidents) and response (automation rules/playbooks), and candidates may incorrectly choose Defender for Endpoint AIR because it only covers endpoints, not the multi-domain incident.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an automation rule in Microsoft Sentinel that runs a playbook to isolate devices and disable accounts
The best approach is to create an automation rule in Microsoft Sentinel that triggers a playbook to isolate devices and disable accounts. Automation rules can be configured to run playbooks automatically when an incident is created, and the playbook can call Microsoft Defender for Endpoint to isolate devices and Microsoft Entra ID to disable accounts. This provides a centralized, automated containment workflow across multiple sources.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use advanced hunting to find all affected devices and accounts
Why it's wrong here
Advanced hunting is a read-only KQL query surface for investigation; it returns device and account records but cannot isolate endpoints or disable Microsoft Entra ID accounts. It would be correct when analysts need to proactively search telemetry for indicators, not when automated containment actions are required.
- ✓
Create an automation rule in Microsoft Sentinel that runs a playbook to isolate devices and disable accounts
Why this is correct
An automation rule triggers a playbook on incident creation, and the playbook calls Defender for Endpoint and Microsoft Entra ID actions to isolate devices and disable accounts. This satisfies the containment requirement without manual intervention.
- ✗
Create a custom detection rule in Microsoft Sentinel to trigger an incident
Why it's wrong here
A custom detection rule only generates new incidents from scheduled queries; it performs no containment actions such as device isolation or account disabling. It would be correct when you need to surface specific suspicious activity as an alert, not when the requirement is automated response across Defender for Endpoint, Office 365 and Microsoft Entra ID.
- ✗
Configure automated investigation and response in Microsoft Defender for Endpoint
Why it's wrong here
Automated investigation and response in Defender for Endpoint only covers Defender for Endpoint alerts and devices; it cannot disable Microsoft Entra ID accounts or act on Defender for Office 365 signals. It would be correct for endpoint-scoped auto-remediation, but the stem requires cross-workload orchestration via Sentinel playbooks.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
2 more ways this is tested on SC-200
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. An organization uses Microsoft Sentinel for security operations. A security engineer needs to automatically disable a compromised user account in Microsoft Entra ID when a high-severity incident is created in Sentinel. Which feature should the engineer use?
easy- A.Analytics rule
- B.Workbook
- ✓ C.Automation rule with a playbook
- D.Hunting query
Why C: To automatically disable a compromised user account in Microsoft Entra ID when a high-severity incident is created in Sentinel, the engineer should use an automation rule that triggers a playbook. Automation rules in Microsoft Sentinel allow you to define conditions (e.g., incident severity) and then invoke a playbook, which can contain the logic to call Microsoft Graph or Entra ID to disable the user. This is the standard method for automated response.
Variation 2. Your organization uses Microsoft Sentinel and has enabled UEBA (User and Entity Behavior Analytics). You notice a series of incidents involving anomalous logon times for a privileged user. You want to automate the response to disable the user's account in Microsoft Entra ID when such incidents are created. What should you configure?
hard- ✓ A.Create an automation rule that runs a playbook when an incident from the UEBA analytics rule is created, and configure the playbook to disable the user in Microsoft Entra ID.
- B.Create an analytics rule that triggers on UEBA anomalies and directly disables the user.
- C.Add the user to a watchlist and create a playbook that runs on a schedule.
- D.Configure UEBA to automatically disable the user when anomalous behavior is detected.
Why A: Microsoft Sentinel automation rules can trigger a playbook when an incident is created by a specific analytics rule (e.g., a UEBA-based rule). The playbook, built in Azure Logic Apps, can then use the Microsoft Graph API to disable the user's account in Microsoft Entra ID. This provides a fully automated, event-driven response to anomalous logon time incidents without manual intervention.
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.