SC-200 Manage a security operations environment Practice Question
Which THREE are valid components of a Microsoft Sentinel automation rule?
⚠ Common exam trap
Many candidates confuse the components of an automation rule with those of an analytics rule, mistakenly selecting KQL queries or watchlists as valid automation rule components.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Actions (e.g., Run playbook, Change severity)
Automation rules in Microsoft Sentinel allow you to define actions such as running a playbook or changing the severity of an incident. These actions are executed automatically when the rule's trigger and conditions are met, enabling streamlined incident response without manual intervention.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Actions (e.g., Run playbook, Change severity)
Why this is correct
Actions in a Microsoft Sentinel automation rule are the operational steps that execute when the rule's trigger and conditions are satisfied. These include invoking playbooks, modifying incident severity, assigning ownership, adding tags, or closing the incident. Actions run sequentially in the order defined in the rule and are the only components that actually change the state of the incident or perform external responses.
- ✗
Watchlist
Why it's wrong here
Watchlists are independent data resources in Microsoft Sentinel used to store arbitrary collections of data for correlation, enrichment, and filtering in KQL queries and playbooks. They are not a component of an automation rule, which has only a trigger, conditions, and actions. Automation rules cannot natively reference watchlists as a condition source, making this an incorrect answer.
- ✗
KQL query
Why it's wrong here
KQL queries are used in analytics rules to define detection logic over ingested data, and in playbooks or workbooks for enrichment and visualization. Automation rules, however, do not include any query component; they act on incidents that have already been generated and use structured conditions based on incident attributes and alert properties. Including a KQL query is therefore an invalid component for an automation rule.
- ✓
Conditions (e.g., If severity equals Medium)
Why this is correct
Conditions are the criteria evaluated against each incident that matches the trigger. They are built with both property-based conditions (e.g., severity, status, tag, entity) and alert-based conditions (e.g., alert product name), combined using AND/OR operators. Only incidents that satisfy all conditions will have the rule's actions executed, providing precise control over automation behavior.
- ✓
Trigger (e.g., When incident is created)
Why this is correct
A trigger specifies the event that initiates the evaluation of the automation rule, such as incident creation, incident update, or alert creation. In Microsoft Sentinel, the trigger is selected when the rule is created and determines the scope of evaluation for conditions. For example, a rule triggered 'When incident is created' evaluates the incident immediately after it is generated, before any manual changes are applied.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.