Courseiva

SC-200 Respond to security incidents Practice Question

Exhibit

Refer to the exhibit.
```
{
  "properties": {
    "displayName": "Block malicious IP",
    "triggers": [
      {
        "type": "IncidentCreated",
        "conditions": [
          {
            "condition": "IncidentSeverity",
            "operator": "Equals",
            "value": "High"
          }
        ]
      }
    ],
    "actions": [
      {
        "type": "RunPlaybook",
        "playbookId": "/subscriptions/.../block-ip"
      }
    ]
  }
}
```

Refer to the exhibit. You are reviewing an automation rule in Microsoft Sentinel. What will happen when a new incident with severity Medium is created?

⚠ Common exam trap

Many exam-takers assume the rule will trigger and then skip the playbook due to a mismatch, but in reality, the condition check happens first—if the severity does not match, the rule does not trigger at all, and no actions are evaluated.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The rule will not trigger because severity is Medium

The automation rule is configured with a condition that triggers only when the incident severity is 'High'. Since the new incident has a severity of 'Medium', the condition is not met, and the rule does not trigger. Automation rules in Microsoft Sentinel evaluate conditions based on the incident's properties at creation time; if the condition fails, no actions (including playbook execution or incident creation) occur.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The rule will not trigger because severity is Medium

    Why this is correct

    The rule will not trigger because the incident has Medium severity, while the rule's condition explicitly requires an incident severity of High. When an incident is created or updated, Microsoft Sentinel evaluates the rule's trigger conditions against that incident's properties, and a failed condition prevents the rule from executing any actions. Because no action runs, neither the playbook nor any severity update occurs.

  • ✗

    The rule will trigger and create a new incident

    Why it's wrong here

    This is incorrect because automation rules in Microsoft Sentinel do not have an action that creates incidents; they only operate on an incident that already exists or has just been created. Incident creation is performed by analytics rules (scheduled or Microsoft Security) or by a user manually creating one. Even if the automation rule had triggered, it could not generate a new incident object—its actions are limited to modifying the triggering incident or invoking a playbook.

  • ✗

    The rule will trigger and run the playbook

    Why it's wrong here

    This option overlooks the failure of the rule's condition: the rule only runs a playbook when the incident severity equals High, and the exhibited incident is Medium. A playbook action is merely one possible action in an automation rule and is only executed after the rule's trigger conditions have been satisfied. Since the condition fails, the playbook is never invoked, so this outcome cannot happen.

  • ✗

    The rule will update the incident severity to High

    Why it's wrong here

    Although automation rules can change an incident's severity as one of their supported actions, the rule in the exhibit does not define a severity-update action, and more importantly, it requires High severity to trigger. With a Medium incident, the rule's condition evaluates to false, so no actions—including any severity modification—are executed. The rule would only be able to update severity if its condition passed and a corresponding action were explicitly configured.

  • ✗

    The rule will trigger but skip the playbook

    Why it's wrong here

    Incorrect because the automation rule does not trigger at all; there is no partial or conditional execution that would allow it to skip a playbook action. A "skip" scenario would occur only if the rule condition passed but the playbook action failed, timed out, or was otherwise scoped out—not when the incident severity is Medium. Here, the rule engine halts at condition evaluation, so it never reaches the playbook step.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.