Courseiva

SC-200 Respond to security incidents Practice Question

Exhibit

Refer to the exhibit.
```json
{
  "properties": {
    "displayName": "Block malicious IPs",
    "trigger": {
      "type": "IncidentCreated",
      "conditions": [
        {
          "name": "High severity",
          "field": "Severity",
          "operator": "Equals",
          "value": "High"
        }
      ]
    },
    "actions": [
      {
        "name": "Run playbook",
        "type": "RunPlaybook",
        "properties": {
          "logicAppResourceId": "/subscriptions/.../block-ip",
          "tenantId": "..."
        }
      }
    ]
  }
}

The exhibit shows an automation rule in Microsoft Sentinel. The analyst reports that the playbook is not triggered for high-severity incidents. What is the most likely cause?

⚠ Common exam trap

Watch out — candidates often assume the rule will re-evaluate conditions whenever the incident changes, but Sentinel's automation rules only evaluate the trigger condition at the moment of incident creation or update, not continuously, so a severity change after creation will not fire a rule set to 'When incident is created.'

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The rule triggers only on incident creation, not on updates.

The automation rule is configured to trigger 'When incident is created,' which means it only runs the playbook at the moment the incident is first generated. If the incident's severity is updated after creation (e.g., from medium to high), the rule does not re-trigger, so the playbook will not execute for that high-severity incident. This is the most likely cause because the analyst reports that high-severity incidents are not triggering the playbook, and the rule's trigger condition explicitly excludes updates.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The playbook resource ID is invalid.

    Why it's wrong here

    The playbook resource ID is not invalid. In Microsoft Sentinel, automation rules reference playbooks by their full Azure resource ID at configuration time. The rule editor validates this identifier when the rule is saved and would immediately surface an error if the ID were malformed, deleted, or from the wrong subscription. Since the rule saved successfully and appears as active, the resource ID is valid.

  • ✗

    The condition syntax is incorrect.

    Why it's wrong here

    The condition syntax is not incorrect. The automation rule uses the standard expression format 'Property: operator - value', where 'Severity equals High' is a valid comparison. Sentinel's condition builder only accepts recognized operators and property names; an invalid condition would be rejected during rule creation. The exhibit clearly shows a properly formed severity condition, so syntax is not the issue.

  • ✗

    The tenant ID is missing.

    Why it's wrong here

    The tenant ID is not missing. The automation rule is scoped to the Sentinel workspace, and the tenant is implicitly derived from the workspace's subscription and shown in the resource identifiers displayed in the exhibit. All playbooks and logic app connectors referenced by the rule are in that same tenant, so no separate tenant ID needs to be provided. The rule would not function if the tenant were absent, but the exhibit proves it is present.

  • ✓

    The rule triggers only on incident creation, not on updates.

    Why this is correct

    The rule triggers only on incident creation, not on updates. The automation rule's trigger is set to 'When incident created', which means it evaluates only at the moment an incident is generated. If an existing incident is later modified to raise its severity to 'High', the rule will not run because it does not subscribe to incident update events. To handle such changes, the rule would need to use the 'When incident update' trigger or include both creation and update triggers.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.