SC-200 Manage a security operations environment Practice Question
Which THREE components are part of Microsoft Sentinel's SOAR capabilities? (Choose three.)
⚠ Common exam trap
A common mix-up: candidates confuse data enrichment or visualization tools (Workbooks, Watchlists) with SOAR components, when only incident management, automation rules, and playbooks directly enable automated response and orchestration workflows.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Incident management
Incident management is a core SOAR component in Microsoft Sentinel because it provides the structured workflow for security analysts to triage, investigate, and respond to security incidents. It integrates with automation rules and playbooks to orchestrate response actions, enabling consistent and efficient handling of threats.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Workbooks
Why it's wrong here
Workbooks in Microsoft Sentinel are built on Azure Workbooks and provide interactive visualizations, dashboards, and reporting views of collected security data. They are read-only analytical tools that help analysts understand trends and metrics, but they do not execute automated response actions or orchestrate incident response workflows. Because SOAR is about automation and orchestration of threat response, workbooks are a reporting component, not a SOAR component.
- ✓
Incident management
Why this is correct
Incident management is a core SOAR component in Microsoft Sentinel because incidents serve as the central case-management entity for investigation and response. Sentinel's SOAR capabilities are centered on the full incident lifecycle—creation, assignment, triage, investigation, and resolution—enabling consistent handling. Incident management integrates with automation rules and playbooks to drive orchestrated response, making it essential to the SOAR framework.
- ✗
Watchlists
Why it's wrong here
Watchlists are collections of data (such as high-value IPs, compromised accounts, or sensitive hostnames) that are stored and referenced for enrichment, correlation, and filtering in analytics rules and hunting queries. They are static reference data, not automation logic, and they never trigger or execute response actions on their own. While useful for detection and investigation, watchlists are a data management feature, not a SOAR component.
- ✓
Automation rules
Why this is correct
Automation rules in Microsoft Sentinel are a key SOAR element because they provide centrally managed, code-free automation that runs when incidents are created or updated. These rules can automatically assign incidents, modify severity, add tags, apply custom status, and invoke playbooks, ensuring consistent response handling without manual intervention. As the control plane that triggers orchestrated actions, automation rules are integral to Sentinel's SOAR functionality.
- ✓
Playbooks
Why this is correct
Playbooks are the execution engine of Microsoft Sentinel's SOAR, built on Azure Logic Apps to run multi-step response workflows. They can be triggered by automation rules or manually through incident actions, and they carry out tasks such as enriching alerts with threat intelligence, quarantining compromised entities, or sending outbound notifications to ticketing systems. Playbooks automate and orchestrate response actions via Logic Apps connectors, making them a foundational SOAR component.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.