Courseiva

Microsoft Sentinel Automation Rule Severity Condition

Exhibit

Refer to the exhibit.
```json
{
  "properties": {
    "displayName": "Isolate Compromised Device",
    "trigger": {
      "type": "SecurityIncident",
      "conditions": [
        {
          "property": "IncidentSeverity",
          "operator": "Equals",
          "value": "High"
        },
        {
          "property": "AlertTitle",
          "operator": "ContainsAny",
          "value": ["Malware", "Ransomware"]
        }
      ]
    },
    "actions": [
      {
        "type": "RunPlaybook",
        "playbookId": "<playbook-id>"
      }
    ]
  }
}
```

Refer to the exhibit. You have created an automation rule in Microsoft Sentinel with the above configuration. The playbook isolates the device and disables the user account. After enabling the rule, you notice that a low-severity incident containing an alert titled 'Ransomware Behavior' did NOT trigger the automation. What is the most likely reason?

Quick Answer

The answer is that the automation rule severity condition is not triggering because the rule is configured to trigger only on incidents with a severity of High, while the incident in question has a Low severity. This is a fundamental aspect of how Microsoft Sentinel automation rules evaluate conditions: the severity condition uses an exact match operator, so any incident not meeting the specified severity level is automatically excluded from triggering the playbook. On the SC-200 exam, this scenario tests your understanding of how trigger conditions work in combination with incident properties, and a common trap is assuming that a broader severity range or a "greater than" logic applies when it does not. Remember that automation rules evaluate each condition independently and require an exact match for severity unless you explicitly configure multiple conditions or use a different operator. A helpful memory tip is "severity is a gate, not a filter"—if the severity doesn't match exactly, the rule won't even look at other conditions like alert titles.

⚠ Common exam trap

The trap is assuming the playbook or operator is at fault when the real issue is a condition mismatch — always check the rule's severity/status filters against the incident that failed to trigger.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The incident severity is Low, but the rule only triggers on High severity

Microsoft Sentinel automation rules have a condition set that includes severity; if the rule is configured to trigger only on High-severity incidents, a Low-severity incident will never fire the rule regardless of the alert title. The exhibit shows the rule's conditions, and the most likely mismatch is the severity filter. The playbook itself is not the issue because the rule simply never evaluated to true for this incident.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The 'ContainsAny' operator does not match single values

    Why it's wrong here

    ContainsAny matches when any listed value appears in the alert name, so a single-value list still matches 'Ransomware Behavior'. It tempts because operator semantics are a common automation-rule pitfall, but the actual failure here lies in the rule's severity or product condition, not the operator.

  • ✗

    The automation rule does not have permission to run the playbook

    Why it's wrong here

    Sentinel automation rules run playbooks using the Microsoft Sentinel service principal or a configured managed identity, so missing playbook permissions would surface as a run failure, not a silent non-trigger. The rule simply did not match the incident's severity or title conditions, so the playbook never fired.

  • ✗

    The playbook ID is invalid

    Why it's wrong here

    An invalid playbook ID would surface as a failed action at run time, not as the rule silently skipping the incident; the automation rule itself evaluates conditions before invoking any playbook. It tempts because playbook wiring errors do break automation, but only after a matching incident triggers the rule.

  • ✓

    The incident severity is Low, but the rule only triggers on High severity

    Why this is correct

    The rule's condition filters on High severity, so a Low-severity incident falls outside its trigger scope entirely. Microsoft Sentinel evaluates automation rule conditions against incident properties at creation; severity mismatch prevents any playbook run, regardless of the alert title. Raising the incident's severity or broadening the rule condition would allow execution.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

2 more ways this is tested on SC-200

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Refer to the exhibit. An automation rule is configured as shown. When will the playbook be triggered?

medium
  • A.When any incident is created from Microsoft Defender for Endpoint
  • B.When a new incident with any severity contains 'Malware' in the title
  • C.When an incident is updated to High severity
  • ✓ D.When a new incident is created with severity High, from Microsoft Defender for Endpoint, and with 'Malware' in the title

Why D: In Microsoft Sentinel automation rules, all configured conditions are evaluated with AND logic — every condition must be true for the rule to fire. The exhibit shows three conditions: incident severity = High, the incident must be created (not updated), and the title must contain 'Malware'. Additionally, the rule is scoped to incidents originating from Microsoft Defender for Endpoint. Therefore, the playbook triggers only when a new incident is created that is High severity, sourced from Defender for Endpoint, and has 'Malware' in the title.

Variation 2. Refer to the exhibit. You are reviewing an automation rule in Microsoft Sentinel. What will happen when a new incident with severity Medium is created?

hard
  • ✓ A.The rule will not trigger because severity is Medium
  • B.The rule will trigger and create a new incident
  • C.The rule will trigger and run the playbook
  • D.The rule will update the incident severity to High
  • E.The rule will trigger but skip the playbook

Why A: The automation rule is configured with a condition that triggers only when the incident severity is 'High'. Since the new incident has a severity of 'Medium', the condition is not met, and the rule does not trigger. Automation rules in Microsoft Sentinel evaluate conditions based on the incident's properties at creation time; if the condition fails, no actions (including playbook execution or incident creation) occur.

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.