SC-200 Respond to security incidents Practice Question
Exhibit
Refer to the exhibit.
```json
{
"properties": {
"displayName": "Phishing Incident Response",
"triggers": [
{
"type": "Alert",
"conditions": [
{
"field": "alertName",
"operator": "Equals",
"value": "Phishing email delivered"
}
]
}
],
"actions": [
{
"type": "RunPlaybook",
"playbookId": "/subscriptions/.../playbooks/QuarantineEmail"
}
]
}
}
```Refer to the exhibit. You are configuring an automation rule in Microsoft Sentinel. The JSON snippet defines an automation rule. What is the expected behavior of this rule?
⚠ Common exam trap
Watch out — candidates often confuse the trigger condition (alert creation vs. incident creation) and assume the rule directly performs an action like sending an email or modifying severity, when in fact the rule only triggers a playbook that performs those actions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It runs a playbook to quarantine an email when a specific alert is generated
The automation rule is triggered when a specific alert is generated (as defined by the trigger condition), and it runs a playbook that contains logic to quarantine an email. In Microsoft Sentinel, automation rules can be configured to trigger on alert creation and execute a playbook, which in this case performs the quarantine action.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
It creates an incident when a phishing email is detected
Why it's wrong here
Automation rules do not create incidents; they act on an existing alert or incident after it is generated. In Microsoft Sentinel, incident creation is performed by the analytics rule based on its alert grouping and incident configuration, not by an automation rule. This rule triggers on an alert, so it can only execute a playbook and cannot instantiate a new incident.
- ✗
It sends an email to the security team when an incident is created
Why it's wrong here
Microsoft Sentinel automation rules lack a native 'send email' action; email notifications require a playbook with a connector such as Outlook or Teams. In this exhibit, the rule's only action is running the 'Quarantine' playbook, and no email dispatch is configured. Therefore, this description falsely attributes an email action that does not exist in the rule definition.
- ✓
It runs a playbook to quarantine an email when a specific alert is generated
Why this is correct
The rule's trigger is set to a specific alert name and its action is to invoke a playbook, which is exactly how automated response works in Sentinel. When that alert fires, the rule automatically runs the Quarantine playbook, which likely uses a Microsoft 365 or Defender connector to isolate the offending email. This matches the exhibit: the automation rule reacts to the alert, not to an incident, by executing a playbook.
- ✗
It modifies the incident severity when a playbook runs
Why it's wrong here
Changing incident severity is a distinct automation rule action labeled 'Change severity', but the exhibit shows no such action for this rule. Further, the rule triggers on an alert, and incident severity modifications are only relevant when the trigger is incident creation or update. The playbook execution is the outcome, not a trigger, so severity is never modified by this rule.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.