SC-200 Respond to security incidents Practice Question
Exhibit
Refer to the exhibit.
```
{
"properties": {
"displayName": "Block malicious IP",
"triggers": [
{
"type": "IncidentCreated",
"conditions": [
{
"condition": "IncidentSeverity",
"operator": "Equals",
"value": "High"
}
]
}
],
"actions": [
{
"type": "RunPlaybook",
"playbookId": "/subscriptions/.../block-ip"
}
]
}
}
```Refer to the exhibit. You are reviewing an automation rule in Microsoft Sentinel. What will happen when a new incident with severity Medium is created?
⚠ Common exam trap
Many exam-takers assume the rule will trigger and then skip the playbook due to a mismatch, but in reality, the condition check happens first—if the severity does not match, the rule does not trigger at all, and no actions are evaluated.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The rule will not trigger because severity is Medium
The automation rule is configured with a condition that triggers only when the incident severity is 'High'. Since the new incident has a severity of 'Medium', the condition is not met, and the rule does not trigger. Automation rules in Microsoft Sentinel evaluate conditions based on the incident's properties at creation time; if the condition fails, no actions (including playbook execution or incident creation) occur.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The rule will not trigger because severity is Medium
Why this is correct
The rule will not trigger because the incident has Medium severity, while the rule's condition explicitly requires an incident severity of High. When an incident is created or updated, Microsoft Sentinel evaluates the rule's trigger conditions against that incident's properties, and a failed condition prevents the rule from executing any actions. Because no action runs, neither the playbook nor any severity update occurs.
- ✗
The rule will trigger and create a new incident
Why it's wrong here
This is incorrect because automation rules in Microsoft Sentinel do not have an action that creates incidents; they only operate on an incident that already exists or has just been created. Incident creation is performed by analytics rules (scheduled or Microsoft Security) or by a user manually creating one. Even if the automation rule had triggered, it could not generate a new incident object—its actions are limited to modifying the triggering incident or invoking a playbook.
- ✗
The rule will trigger and run the playbook
Why it's wrong here
This option overlooks the failure of the rule's condition: the rule only runs a playbook when the incident severity equals High, and the exhibited incident is Medium. A playbook action is merely one possible action in an automation rule and is only executed after the rule's trigger conditions have been satisfied. Since the condition fails, the playbook is never invoked, so this outcome cannot happen.
- ✗
The rule will update the incident severity to High
Why it's wrong here
Although automation rules can change an incident's severity as one of their supported actions, the rule in the exhibit does not define a severity-update action, and more importantly, it requires High severity to trigger. With a Medium incident, the rule's condition evaluates to false, so no actions—including any severity modification—are executed. The rule would only be able to update severity if its condition passed and a corresponding action were explicitly configured.
- ✗
The rule will trigger but skip the playbook
Why it's wrong here
Incorrect because the automation rule does not trigger at all; there is no partial or conditional execution that would allow it to skip a playbook action. A "skip" scenario would occur only if the rule condition passed but the playbook action failed, timed out, or was otherwise scoped out—not when the incident severity is Medium. Here, the rule engine halts at condition evaluation, so it never reaches the playbook step.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.