Courseiva

SC-200 Microsoft Sentinel automation rule trigger Practice Question

Exhibit

Refer to the exhibit.
```json
{
  "properties": {
    "displayName": "Malware detection playbook",
    "triggers": [
      {
        "type": "Microsoft.SecurityInsights/AlertRule",
        "conditions": [
          {
            "property": "AlertName",
            "operator": "Contains",
            "value": "malware"
          }
        ]
      }
    ],
    "actions": [
      {
        "type": "Microsoft.SecurityInsights/Incident",
        "order": 1,
        "actionConfiguration": {
          "severity": "High",
          "owner": "tier2",
          "status": "Active"
        }
      }
    ]
  }
}
```

Refer to the exhibit. You are reviewing a Microsoft Sentinel automation rule definition. The rule is intended to automatically change the severity to High, assign to tier2, and set status to Active for incidents triggered by alerts containing 'malware'. However, incidents are not being updated. What is the most likely cause?

⚠ Common exam trap

SC-200 often tests the confusion between alert-level and incident-level triggers — candidates pick 'Alert rule' thinking it covers incidents, but automation rules that mutate incidents require the 'Incident created' trigger.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The trigger type should be 'IncidentCreated', not 'AlertRule'.

Microsoft Sentinel automation rules are triggered by incident-related events, and the correct trigger for acting on newly created incidents is 'Incident created' (IncidentCreated). If the rule is configured with an 'Alert rule' trigger, it fires on alert creation rather than incident creation, so the actions (change severity, assign owner, set status) never execute against the incident object — which is why incidents remain unchanged. Automation rules operate on incidents, not raw alerts, so the trigger must match the incident lifecycle.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The action configuration is missing the 'incident' property.

    Why it's wrong here

    Automation rule actions require the 'incident' property to identify the target entity; omitting it leaves the severity, assignment and status actions without an object to modify. It is tempting because the rule still triggers on alerts, but the incident property would be the correct focus when actions target incident fields rather than alert fields.

  • ✗

    The condition operator 'Contains' is incorrect; should be 'Equals'.

    Why it's wrong here

    'Contains' is a valid condition operator in Microsoft Sentinel automation rules and correctly matches alert names including the substring 'malware'; switching to 'Equals' would require an exact full-string match and break the intended trigger. It is tempting because operators are a common misconfiguration source, but 'Equals' would be correct only for fixed, known alert names.

  • ✓

    The trigger type should be 'IncidentCreated', not 'AlertRule'.

    Why this is correct

    Automation rules act on incidents, so the trigger must be 'IncidentCreated' to fire and apply severity, assignment and status changes. An 'AlertRule' trigger responds to alerts instead, meaning the incident-level actions never execute, which explains why incidents remain unmodified.

  • ✗

    The playbook requires a managed identity to run.

    Why it's wrong here

    Automation rules run natively in Microsoft Sentinel and need no managed identity; that requirement applies to Logic App playbooks invoked by the rule. The likely cause is the rule's conditions or order not matching the 'malware' alerts, so the actions never fire.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.