Microsoft Sentinel Automated Incident Response Features
Which TWO features are available in Microsoft Sentinel to automate incident response?
Quick Answer
The answer is automation rules and playbooks based on Azure Logic Apps. Automation rules allow you to define triggers and actions—like assigning incidents, changing severity, or running a playbook—that execute automatically when an incident or alert is created, providing a lightweight, rule-based approach to incident response. Playbooks, built on Azure Logic Apps, extend this by enabling complex, multi-step workflows such as isolating a compromised VM, blocking an IP, or opening a service desk ticket, all without manual intervention. On the SC-200 exam, this distinction is critical: automation rules handle simple, immediate triage tasks, while playbooks handle orchestrated response sequences. A common trap is confusing playbooks with Logic Apps themselves—remember that playbooks are the Sentinel-specific wrapper that integrates Logic Apps directly into the incident lifecycle. Memory tip: think of automation rules as the “if-this-then-that” for incidents, and playbooks as the “full recipe” for response actions.
⚠ Common exam trap
A common mix-up: candidates confuse detection or analysis tools (Workbooks, KQL, UEBA) with automation tools, failing to recognize that only Playbooks and Automation Rules provide the actual execution of response actions in Sentinel.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Playbooks based on Azure Logic Apps.
Playbooks based on Azure Logic Apps (A) are the core automation mechanism in Microsoft Sentinel: they are Logic Apps workflows triggered by analytics rules or incidents that can run actions such as blocking an IP, posting to Teams, or opening a ticket, so they directly automate incident response. Automation rules (E) are also correct because they let you centrally manage and orchestrate incident handling — assigning owners, changing severity or status, tagging, and triggering playbooks — without writing code, which is exactly automation of incident response. Workbooks (B) are only for visualization and reporting dashboards, and KQL queries (C) are the query language used for hunting and analytics, not an automation feature. UEBA (D) provides behavioral analytics and entity insights to enrich detection, but it does not itself automate response actions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Playbooks based on Azure Logic Apps.
Why this is correct
Playbooks built on Azure Logic Apps provide the orchestration engine in Microsoft Sentinel, running multi-step response workflows triggered manually or by automation rules. They connect to Microsoft Entra ID, Defender and third-party tools, satisfying the requirement for automated incident response actions such as enrichment, notification and remediation.
- ✗
Workbooks.
Why it's wrong here
Workbooks render interactive dashboards and visual reports from query results; they present data rather than execute response actions against incidents. Automation in Microsoft Sentinel is delivered through playbooks. Workbooks would be the right selection when the requirement is monitoring posture or visualising trends for analysts.
- ✗
Kusto Query Language (KQL) queries.
Why it's wrong here
KQL queries retrieve and analyse log data; they execute only when a human or scheduled analytics rule runs them, so they cannot themselves trigger automated response actions. Automation requires playbooks built on Logic Apps. KQL is the correct choice for hunting, writing detection rules, and building workbooks, not orchestration.
- ✗
UEBA.
Why it's wrong here
UEBA baselines entity behaviour and surfaces anomalous activity as insights; it enriches detection but performs no orchestration or remediation steps. Playbooks provide the automated response capability. UEBA is correct when the scenario asks for behavioural analytics or risk scoring of users and hosts, not automation.
- ✓
Automation rules.
Why this is correct
Automation rules are a native Microsoft Sentinel capability that run lightweight orchestration on incidents: assigning owners, changing severity or status, adding tags and triggering playbooks. They satisfy the automation requirement without external logic app authoring, complementing playbooks for triage-level response.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SC-200
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which TWO of the following are valid ways to automate incident response in Microsoft Sentinel?
medium- ✓ A.Create a playbook using Azure Logic Apps.
- B.Use Azure Functions to run a script.
- C.Use PowerShell to modify incidents via API.
- D.Use Microsoft Power Automate to create a flow.
- ✓ E.Create an automation rule that triggers a playbook.
Why A: Azure Logic Apps is the native workflow engine for Microsoft Sentinel playbooks, allowing security analysts to automate incident response actions such as blocking IPs, resetting passwords, or enriching alerts. Playbooks are triggered by automation rules or directly from incidents, and they leverage hundreds of connectors to integrate with external systems. This is the primary and recommended method for building automated response workflows in Sentinel.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.