Courseiva

SC-200 Manage a security operations environment Practice Question

Which THREE components are part of Microsoft Sentinel's SOAR capabilities? (Choose three.)

⚠ Common exam trap

A common mix-up: candidates confuse data enrichment or visualization tools (Workbooks, Watchlists) with SOAR components, when only incident management, automation rules, and playbooks directly enable automated response and orchestration workflows.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Incident management

Incident management is a core SOAR component in Microsoft Sentinel because it provides the structured workflow for security analysts to triage, investigate, and respond to security incidents. It integrates with automation rules and playbooks to orchestrate response actions, enabling consistent and efficient handling of threats.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Workbooks

    Why it's wrong here

    Workbooks in Microsoft Sentinel are built on Azure Workbooks and provide interactive visualizations, dashboards, and reporting views of collected security data. They are read-only analytical tools that help analysts understand trends and metrics, but they do not execute automated response actions or orchestrate incident response workflows. Because SOAR is about automation and orchestration of threat response, workbooks are a reporting component, not a SOAR component.

  • ✓

    Incident management

    Why this is correct

    Incident management is a core SOAR component in Microsoft Sentinel because incidents serve as the central case-management entity for investigation and response. Sentinel's SOAR capabilities are centered on the full incident lifecycle—creation, assignment, triage, investigation, and resolution—enabling consistent handling. Incident management integrates with automation rules and playbooks to drive orchestrated response, making it essential to the SOAR framework.

  • ✗

    Watchlists

    Why it's wrong here

    Watchlists are collections of data (such as high-value IPs, compromised accounts, or sensitive hostnames) that are stored and referenced for enrichment, correlation, and filtering in analytics rules and hunting queries. They are static reference data, not automation logic, and they never trigger or execute response actions on their own. While useful for detection and investigation, watchlists are a data management feature, not a SOAR component.

  • ✓

    Automation rules

    Why this is correct

    Automation rules in Microsoft Sentinel are a key SOAR element because they provide centrally managed, code-free automation that runs when incidents are created or updated. These rules can automatically assign incidents, modify severity, add tags, apply custom status, and invoke playbooks, ensuring consistent response handling without manual intervention. As the control plane that triggers orchestrated actions, automation rules are integral to Sentinel's SOAR functionality.

  • ✓

    Playbooks

    Why this is correct

    Playbooks are the execution engine of Microsoft Sentinel's SOAR, built on Azure Logic Apps to run multi-step response workflows. They can be triggered by automation rules or manually through incident actions, and they carry out tasks such as enriching alerts with threat intelligence, quarantining compromised entities, or sending outbound notifications to ticketing systems. Playbooks automate and orchestrate response actions via Logic Apps connectors, making them a foundational SOAR component.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.