Courseiva

SC-200 Respond to security incidents Practice Question

Exhibit

Refer to the exhibit.

```json
{
  "properties": {
    "displayName": "Malware detected on endpoint",
    "description": "This automation rule will isolate the device when a malware incident is created.",
    "triggers": [
      {
        "type": "IncidentCreated",
        "conditions": [
          {
            "property": "Severity",
            "operator": "Equals",
            "value": "High"
          },
          {
            "property": "Provider",
            "operator": "Equals",
            "value": "Microsoft Defender for Endpoint"
          },
          {
            "property": "Title",
            "operator": "Contains",
            "value": "Malware"
          }
        ]
      }
    ],
    "actions": [
      {
        "type": "RunPlaybook",
        "playbookId": "/subscriptions/.../providers/Microsoft.Logic/workflows/IsolateDevicePlaybook"
      }
    ]
  }
}
```

Refer to the exhibit. An automation rule is configured as shown. When will the playbook be triggered?

⚠ Common exam trap

SC-200 often tests the assumption that automation rules use OR logic or that any single condition can trigger the playbook, when in fact all conditions are combined with AND.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

When a new incident is created with severity High, from Microsoft Defender for Endpoint, and with 'Malware' in the title

In Microsoft Sentinel automation rules, all configured conditions are evaluated with AND logic — every condition must be true for the rule to fire. The exhibit shows three conditions: incident severity = High, the incident must be created (not updated), and the title must contain 'Malware'. Additionally, the rule is scoped to incidents originating from Microsoft Defender for Endpoint. Therefore, the playbook triggers only when a new incident is created that is High severity, sourced from Defender for Endpoint, and has 'Malware' in the title.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    When any incident is created from Microsoft Defender for Endpoint

    Why it's wrong here

    The exhibit's conditions specify particular severity and entity or title criteria, so a bare Defender for Endpoint source match is insufficient. Source-only triggering would apply if the rule were scoped purely to that service with no additional conditions.

  • ✗

    When a new incident with any severity contains 'Malware' in the title

    Why it's wrong here

    The rule's conditions match on specific analytics rule or service sources and severity thresholds, not free-text title matching. Title-based matching belongs to custom detection rules; automation rules trigger on incident metadata such as severity, status, classification, and service source.

  • ✗

    When an incident is updated to High severity

    Why it's wrong here

    The rule triggers on incident creation, not on subsequent updates. Severity-change triggering applies when the automation rule's trigger is set to 'When incident is updated' with a severity condition, which the exhibit does not show.

  • ✓

    When a new incident is created with severity High, from Microsoft Defender for Endpoint, and with 'Malware' in the title

    Why this is correct

    The rule's conditions combine incident creation, High severity, Microsoft Defender for Endpoint as the detection source, and 'Malware' in the title. All must match simultaneously, so the playbook fires only when every condition is satisfied on a newly created incident.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.