Courseiva
mediumDrag & Drop

SC-200 Practice Question: Order the steps to create a Microsoft Sentinel…

Order the steps to create a Microsoft Sentinel automation rule that automatically closes low-severity incidents.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Step 1: Navigate to the Automation blade in Microsoft Sentinel. Step 2: Create a new automation rule. Step 3: Configure the condition to trigger when an incident is created with severity equals Low. Step 4: Add an action to close the incident and set a comment.

Automation rules are created in the Automation blade, conditions define when to trigger, and actions define what to do.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Step 1: Navigate to the Automation blade in Microsoft Sentinel. Step 2: Create a new automation rule. Step 3: Configure the condition to trigger when an incident is created with severity equals Low. Step 4: Add an action to close the incident and set a comment.

    Why this is correct

    This is the correct sequence. You must first open the Automation blade since the rule-creation wizard is surfaced there, then create a new automation rule to establish the rule resource. After the rule is created, you define the trigger condition—an incident created with severity Low—and then assign the action to close the incident with a comment. The wizard is linear: condition precedes action, and this order matches the product flow.

  • ✗

    Step 1: Create a new automation rule. Step 2: Configure the condition to trigger when an incident is created with severity equals Low. Step 3: Navigate to the Automation blade in Microsoft Sentinel. Step 4: Add an action to close the incident and set a comment.

    Why it's wrong here

    This order is incorrect because the Microsoft Sentinel Automation blade is the container that exposes the 'Create' button; without navigating there first, a new automation rule cannot be created. While the rule is created before the condition is set, the action placement at the end is not the primary flaw—rather, the rule creation step must occur after entering the Automation blade. You cannot open the rule creation wizard directly from another context without first accessing the Automation section.

  • ✗

    Step 1: Navigate to the Automation blade in Microsoft Sentinel. Step 2: Configure the condition to trigger when an incident is created with severity equals Low. Step 3: Create a new automation rule. Step 4: Add an action to close the incident and set a comment.

    Why it's wrong here

    This order fails because you attempt to configure the incident-creation severity condition before the automation rule exists. In Sentinel, the condition editor is part of the automation rule creation wizard, so there is no rule resource to attach the condition to until the rule is created. Navigating to the Automation blade is necessary, but skipping the rule-creation step causes the condition configuration step to have no target.

  • ✗

    Step 1: Navigate to the Automation blade in Microsoft Sentinel. Step 2: Create a new automation rule. Step 3: Add an action to close the incident and set a comment. Step 4: Configure the condition to trigger when an incident is created with severity equals Low.

    Why it's wrong here

    Although the Automation blade and rule creation are correctly ordered, the rule's trigger condition must be defined prior to the action, not after it. The Sentinel rule builder enforces a sequence where you specify the incident or alert conditions that determine when automation runs, and only then assign actions such as closing the incident and adding a comment. Adding the action first leaves the rule without its conditional trigger, which in the actual UI precedes the action configuration pane.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.