SC-200 Respond to security incidents Practice Question
Exhibit
Refer to the exhibit.
```json
{
"properties": {
"displayName": "Malware detected on endpoint",
"description": "This automation rule will isolate the device when a malware incident is created.",
"triggers": [
{
"type": "IncidentCreated",
"conditions": [
{
"property": "Severity",
"operator": "Equals",
"value": "High"
},
{
"property": "Provider",
"operator": "Equals",
"value": "Microsoft Defender for Endpoint"
},
{
"property": "Title",
"operator": "Contains",
"value": "Malware"
}
]
}
],
"actions": [
{
"type": "RunPlaybook",
"playbookId": "/subscriptions/.../providers/Microsoft.Logic/workflows/IsolateDevicePlaybook"
}
]
}
}
```Refer to the exhibit. An automation rule is configured as shown. When will the playbook be triggered?
⚠ Common exam trap
SC-200 often tests the assumption that automation rules use OR logic or that any single condition can trigger the playbook, when in fact all conditions are combined with AND.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
When a new incident is created with severity High, from Microsoft Defender for Endpoint, and with 'Malware' in the title
In Microsoft Sentinel automation rules, all configured conditions are evaluated with AND logic — every condition must be true for the rule to fire. The exhibit shows three conditions: incident severity = High, the incident must be created (not updated), and the title must contain 'Malware'. Additionally, the rule is scoped to incidents originating from Microsoft Defender for Endpoint. Therefore, the playbook triggers only when a new incident is created that is High severity, sourced from Defender for Endpoint, and has 'Malware' in the title.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
When any incident is created from Microsoft Defender for Endpoint
Why it's wrong here
The exhibit's conditions specify particular severity and entity or title criteria, so a bare Defender for Endpoint source match is insufficient. Source-only triggering would apply if the rule were scoped purely to that service with no additional conditions.
- ✗
When a new incident with any severity contains 'Malware' in the title
Why it's wrong here
The rule's conditions match on specific analytics rule or service sources and severity thresholds, not free-text title matching. Title-based matching belongs to custom detection rules; automation rules trigger on incident metadata such as severity, status, classification, and service source.
- ✗
When an incident is updated to High severity
Why it's wrong here
The rule triggers on incident creation, not on subsequent updates. Severity-change triggering applies when the automation rule's trigger is set to 'When incident is updated' with a severity condition, which the exhibit does not show.
- ✓
When a new incident is created with severity High, from Microsoft Defender for Endpoint, and with 'Malware' in the title
Why this is correct
The rule's conditions combine incident creation, High severity, Microsoft Defender for Endpoint as the detection source, and 'Malware' in the title. All must match simultaneously, so the playbook fires only when every condition is satisfied on a newly created incident.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.