Courseiva

SC-200 Manage a security operations environment Practice Question

Exhibit

{
  "properties": {
    "displayName": "Test Automation Rule",
    "order": 1,
    "triggers": [
      {
        "type": "IncidentCreated",
        "conditions": [
          {
            "property": "IncidentStatus",
            "operator": "Equals",
            "value": "Active"
          },
          {
            "property": "Severity",
            "operator": "Equals",
            "value": "High"
          }
        ]
      }
    ],
    "actions": [
      {
        "type": "RunPlaybook",
        "order": 1,
        "playbookId": "/subscriptions/.../providers/Microsoft.Logic/workflows/MyPlaybook"
      }
    ]
  }
}

Refer to the exhibit. You have an automation rule defined as shown. The rule is enabled but never triggers. What is the most likely reason?

⚠ Common exam trap

Microsoft often tests the subtle difference between incident status values ('New' vs 'Active') and the fact that incidents are created as 'New', not 'Active', causing candidates to overlook the condition mismatch.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The condition requires incident status 'Active', but incidents start as 'New'.

The automation rule triggers on incident creation, but the condition requires the incident status to be 'Active'. In Microsoft Sentinel, incidents are created with a status of 'New', not 'Active'. Therefore, the condition is never met, and the rule never triggers. To fix this, the condition should either be removed or changed to include 'New' status.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The playbook resource ID is incomplete.

    Why it's wrong here

    The playbook resource ID in the exhibit is actually a fully qualified Azure resource path for a Logic App workflow. Even if a portion of the ID were truncated, the automation rule would still evaluate its conditions and trigger the action—only then would the playbook invocation fail due to the invalid reference. Thus an incomplete ID is not the reason the rule never runs; the condition mismatch is what prevents the rule from firing at all.

  • ✓

    The condition requires incident status 'Active', but incidents start as 'New'.

    Why this is correct

    When Microsoft Sentinel creates an incident, its Status property is always set to 'New' by default, regardless of the severity or entity classification. The automation rule's condition requires Status to equal 'Active', which is a later state an incident enters only after manual triage or another automation rule changes it. Because the trigger fires at incident creation—before any status transition—the condition evaluates to false and the rule does not execute. This is the definitive cause of the problem.

  • ✗

    The trigger type should be 'AlertCreated' instead of 'IncidentCreated'.

    Why it's wrong here

    Automation rules in Microsoft Sentinel are exclusively event-driven by incident lifecycle events such as 'When incident is created' or 'When incident is updated'; there is no 'AlertCreated' trigger type for automation rules. The 'AlertCreated' concept applies to legacy playbook triggering or analytics rule automation, not to the rule shown. Therefore, leaving the trigger as IncidentCreated is correct and changing it to AlertCreated would be syntactically impossible in this context.

  • ✗

    The rule order is set to 1, which is too low.

    Why it's wrong here

    The order property in an automation rule defines its priority relative to other rules, with lower numbers executing earlier. Setting the order to 1 ensures this rule runs first when multiple automation rules exist—it in no way suppresses execution. Since the rule's issue is that its condition never matches the initial incident state, the order value is irrelevant to why the rule fails to trigger.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.