Courseiva

SC-200 Manage a security operations environment Practice Question

Which THREE components are part of the Microsoft Sentinel SOAR capabilities? (Select THREE.)

⚠ Common exam trap

It's easy for candidates to confuse Workbooks (visualization) or Analytics rules (detection) with SOAR components, because they are all part of Sentinel's core features, but only connectors, playbooks, and automation rules directly enable orchestration and automated response.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Connectors

Connectors are part of Microsoft Sentinel's SOAR capabilities because they enable the ingestion of security alerts and events from various sources, which is the foundational step for triggering automated responses. Without connectors, Sentinel cannot receive the data needed to initiate playbooks or automation rules, making them an essential component of the SOAR workflow.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Connectors

    Why this is correct

    Connectors are the integration layer that enables Sentinel to ingest threat intelligence, alerts, and other data from external sources, and also to take outbound actions across connected systems like ServiceNow, Teams, or Microsoft Entra ID. In the SOAR context, connectors provide the input triggers and output actions that playbooks rely on to orchestrate response workflows beyond Sentinel's native data. Without connectors, automated response would be limited to internal Sentinel data, making them an essential component of the SOAR architecture.

  • ✗

    Workbooks

    Why it's wrong here

    Workbooks are interactive dashboards that visualize data using KQL queries, providing analysts with at-a-glance monitoring, reporting, and investigation views of Sentinel data. They are a SIEM feature designed for operational oversight and trend analysis, not a component of the SOAR engine that executes automated response actions. While workbooks can help post-incident review or track automation metrics, they do not trigger, orchestrate, or run any remediation workflows, so they are incorrect in this context.

  • ✓

    Playbooks

    Why this is correct

    Playbooks are cloud-native workflows built on Azure Logic Apps that define the actual automated response procedures in Sentinel, such as isolating an affected VM, submitting indicators to threat intelligence platforms, or opening an IT ticketing record. They consume connector-based inputs and execute the sequence of security actions, acting as the executable 'security orchestration' logic in SOAR. Playbooks are triggered by automation rules (or alert rules) and are a core SOAR component because they carry out the real-time response actions.

  • ✗

    Analytics rules

    Why it's wrong here

    Analytics rules are KQL-based detection queries that continuously scan ingested data to identify suspicious activity and generate alerts or incidents based on patterns or thresholds. They belong to the SIEM detection portion of Sentinel, which is solely concerned with identifying potential threats, not with orchestrating or executing a response. Analytics rules can optionally invoke playbooks, but the rule itself only performs detection, not automated response, so it is not part of the SOAR stack.

  • ✓

    Automation rules

    Why this is correct

    Automation rules are the control-plane mechanism that centrally define conditions and actions for incident orchestration, determining when a playbook should be launched based on triggers like incident creation, severity level, or state changes. They separate the 'what should happen' logic from the 'how it happens' logic in playbooks, allowing security teams to manage response workflows without editing individual playbooks. This event-driven triggering behavior makes automation rules a core SOAR component, sitting alongside playbooks and connectors.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SC-200

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Which THREE components are part of Microsoft Sentinel's SOAR capabilities? (Choose three.)

medium
  • A.Workbooks
  • ✓ B.Incident management
  • C.Watchlists
  • ✓ D.Automation rules
  • ✓ E.Playbooks

Why B: Incident management is a core SOAR component in Microsoft Sentinel because it provides the structured workflow for security analysts to triage, investigate, and respond to security incidents. It integrates with automation rules and playbooks to orchestrate response actions, enabling consistent and efficient handling of threats.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.