SC-200 Manage a security operations environment Practice Question
Exhibit
Refer to the exhibit.
```json
{
"type": "Microsoft.Security/automations",
"apiVersion": "2019-01-01-preview",
"name": "BlockMaliciousIP",
"properties": {
"description": "Block malicious IP in firewall",
"isEnabled": true,
"actions": [
{
"type": "LogicApp",
"order": 1,
"logicAppResourceId": "/subscriptions/.../resourceGroups/.../providers/Microsoft.Logic/workflows/BlockIP",
"actionParameters": {
"@odata.type": "#Microsoft.Azure.Security.AlertSimulator.LogicAppActionParameters"
}
}
],
"scopes": [
"/subscriptions/..."
],
"sources": [
{
"eventSource": "Alerts"
}
]
}
}
```Refer to the exhibit. You are reviewing an Azure Security Center automation (now Microsoft Defender for Cloud) that should automatically trigger a Logic App when an alert is generated. However, the automation is not triggering. What is the most likely cause?
⚠ Common exam trap
Candidates often assume the automation will trigger on all alerts by default, but Microsoft Defender for Cloud requires explicit trigger conditions; otherwise, the automation exists but never fires.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The automation is missing the 'triggers' property to filter on specific alert types
Microsoft Defender for Cloud automation requires a 'triggers' property to define which alert types should invoke the Logic App. Without this property, the automation is created but never fires, as it has no conditions to match incoming alerts. The exhibit shows the automation resource is configured, but missing the triggers array means no alerts will trigger the Logic App.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The action type is incorrect; it should be 'EventHub'
Why it's wrong here
LogicApp is one of the valid action types for Defender for Cloud automations, alongside EventHub and LogAnalytics. The action's `type` value correctly identifies a logic app as the target, and it matches the populated `logicAppResourceId`. Changing it to 'EventHub' would actually be inappropriate because the resource ID references a logic app, not an event hub namespace.
- ✗
The logicAppResourceId is missing
Why it's wrong here
The `logicAppResourceId` field is explicitly present in the JSON and contains the full Azure resource ID for the Logic App. A missing resource ID would produce a validation error about a required reference, but none occurs here because the value is supplied. The action is therefore properly wired to the intended Logic App.
- ✗
The apiVersion is invalid
Why it's wrong here
The apiVersion '2019-01-01-preview' is a legitimate, supported version for the Microsoft.Security/automations resource provider. Azure Resource Manager accepts this version, so the automation rule would not fail validation on that basis. Any issue with the automation must be found elsewhere in the JSON.
- ✓
The automation is missing the 'triggers' property to filter on specific alert types
Why this is correct
The automation is missing the `triggers` property, which is mandatory in Microsoft.Security/automations to filter on specific alert types or other conditions. Without a trigger, the automation has no event criteria to evaluate, so it will never fire the Logic App. The `triggers` property defines which alerts, severities, or states activate the action, making it essential for the rule to function.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.