SC-200 Respond to security incidents Practice Question
During an incident response, a SOC analyst needs to automatically collect relevant evidence from multiple Microsoft 365 services. Which Microsoft Sentinel playbook trigger should the analyst configure?
⚠ Common exam trap
Many candidates confuse the Alert trigger (which fires on individual alerts) with the Incident trigger (which aggregates alerts into incidents), and fail to recognize that only the Incident trigger has the dedicated 'Collect evidence' action for multi-service evidence gathering.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Sentinel Incident trigger with action 'Collect evidence'.
The Microsoft Sentinel Incident trigger with the 'Collect evidence' action is specifically designed to automate evidence collection across Microsoft 365 services during incident response. This trigger fires when an incident is created or updated, allowing the playbook to gather relevant data from sources like Microsoft Defender for Endpoint, Microsoft 365 Defender, and Microsoft Entra ID without manual intervention.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Sentinel Playbook trigger 'When a response action is executed'.
Why it's wrong here
The name 'When a response action is executed' is not a valid trigger in the Microsoft Sentinel Logic Apps connector. Sentinel playbooks are initiated by dedicated triggers such as 'When a Microsoft Sentinel incident is created/updated' or 'When a Microsoft Sentinel alert is created.' Because this trigger does not exist, a playbook cannot be configured with it for automatic evidence collection during incident creation.
- ✗
Microsoft Sentinel Scheduled Analytics rule trigger.
Why it's wrong here
A scheduled analytics rule trigger is not a playbook trigger at all; scheduled rules are used to generate alerts based on query frequency. Playbooks do not use scheduled rules as their trigger. For automated evidence collection, the playbook must be triggered by the creation of an incident or alert, not by a schedule.
- ✗
Microsoft Sentinel Alert trigger.
Why it's wrong here
The Microsoft Sentinel Alert trigger fires on each individual alert, so it is useful for alert-centric automation, but not ideal for orchestrating multi-service evidence collection for an incident. Incident response typically requires correlation of multiple alerts and enrichment from several sources, which is done at the incident level. Triggering on the alert would be too granular and would miss the broader incident context.
- ✓
Microsoft Sentinel Incident trigger with action 'Collect evidence'.
Why this is correct
The Microsoft Sentinel Incident trigger with the action 'Collect evidence' is the correct choice because it fires when an incident is created, providing a single orchestration point for gathering evidence across multiple sources. This trigger can invoke a playbook automatically via an automation rule or manually, and the playbook can connect to various connectors to collect related evidence and append it to the incident. This aligns with best practice for incident-centric automation.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.