Courseiva

SC-200 Respond to security incidents Practice Question

Exhibit

Refer to the exhibit.

```json
{
  "properties": {
    "displayName": "Block Malicious IP",
    "description": "Playbook to block IP in firewall",
    "triggers": [
      {
        "type": "Microsoft.SecurityInsights/incidents",
        "conditions": [
          {
            "property": "Severity",
            "operator": "Equals",
            "value": "High"
          }
        ]
      }
    ],
    "actions": [...]
  }
}
```

The exhibit shows a partial playbook trigger configuration in Microsoft Sentinel. When will this playbook be triggered?

⚠ Common exam trap

Many candidates confuse the trigger event (creation vs. update) or overlook the severity condition, assuming the playbook runs on any incident creation when the exhibit clearly shows a filter for High severity.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

When an incident of severity High is created.

The playbook trigger configuration shown in the exhibit specifies that the playbook runs when an incident is created, and it includes a condition that filters for incidents with a severity of High. In Microsoft Sentinel, playbook triggers can be set on incident creation or alert creation, and conditions like severity are evaluated at the time of the trigger event. Here, the trigger is explicitly set to 'When an incident is created' with a severity condition of 'High', so the playbook only fires when a new incident with High severity is created.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    When an incident is updated with severity High.

    Why it's wrong here

    This trigger is configured for incident creation, not for incident updates. The condition block is evaluated only when a new incident is created, and the playbook will not fire when an existing incident subsequently has its severity changed to High. The update action would require a separate automation rule or trigger configured for incident update events, which this exhibit does not use.

  • ✗

    When an alert is generated with severity High.

    Why it's wrong here

    This playbook triggers on the Incident entity, not on Alert entities. While alerts can generate incidents, the trigger condition directly inspects the incident's severity property, not the severity of any underlying alert. Even if an alert arrives with High severity, the incident creation must also have High severity for this playbook to run, and the trigger itself is not bound to the alert creation event.

  • ✓

    When an incident of severity High is created.

    Why this is correct

    This is correct because the trigger explicitly references an incident creation event and includes a condition that checks the incident's severity equals High. Only new incidents that meet this severity requirement will activate the playbook; all other incidents will be ignored by this trigger. The condition is evaluated as part of the incident creation flow, so the playbook runs immediately when a High-severity incident is born.

  • ✗

    When any incident is created.

    Why it's wrong here

    The trigger condition narrows the scope to incidents whose severity is exactly High. Therefore, not every incident creation will trigger the playbook; only those with the High severity property will match. Incidents created with Low, Medium, or Informational severities will not pass the condition and will not invoke the playbook.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.