Courseiva

SC-200 Manage a security operations environment Practice Question

Which THREE components are required to enable automation in Microsoft Sentinel? (Choose three.)

⚠ Common exam trap

Test-takers frequently confuse the licensing requirements for Power Automate (Option A) with the actual compute engine (Azure Logic Apps) needed for playbooks, or they mistakenly think Entra ID P2 (Option C) is required for automation when it is only needed for identity protection features.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Playbooks based on Azure Logic Apps

Playbooks based on Azure Logic Apps are required because they provide the workflow automation engine that executes response actions in Microsoft Sentinel. Without a Logic Apps resource to define the steps (e.g., triggers, conditions, and actions), there is no executable automation to run when an incident or alert is generated.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Microsoft Power Automate license

    Why it's wrong here

    A separate Microsoft Power Automate license is not required because Microsoft Sentinel playbooks are built directly on Azure Logic Apps, not Power Automate. Logic Apps is a Microsoft Azure service with its own consumption or standard pricing model, and Sentinel automation invokes Logic Apps workflows via automation rules or incident triggers. Therefore, omitting a Power Automate license does not prevent or limit automation in Microsoft Sentinel.

  • ✓

    Playbooks based on Azure Logic Apps

    Why this is correct

    Playbooks based on Azure Logic Apps are the execution component that actually performs automated response actions in Microsoft Sentinel. These playbooks represent the procedural logic—such as isolating a compromised host, resetting credentials, or enriching an incident—by calling APIs and orchestrating Azure services. Without a playbook, an automation rule has no substantive task to run, so playbooks are a required foundation for enabling security automation.

  • ✗

    Microsoft Entra ID P2 license

    Why it's wrong here

    Microsoft Entra ID P2 licensing is unrelated to enabling Microsoft Sentinel automation; it provides Identity Protection, risky sign-in policies, and entitlement management. Sentinel automation depends on Azure Logic Apps, automation rules, and identity authentication through a managed identity or service principal. You can deploy and run Sentinel playbooks entirely without any Microsoft Entra ID P2 license, provided the Logic App identity has appropriate RBAC permissions.

  • ✓

    Managed identity or service principal for authentication

    Why this is correct

    A managed identity or service principal is the authentication mechanism that lets an Azure Logic App call Microsoft Sentinel and other resources during playbook execution. Without this identity, the Logic App cannot prove who it is or obtain authorized access to perform actions such as updating incidents, fetching entities, or modifying Azure resources. This is a required component because every authenticated API call from a playbook needs a security principal with permissioned access—commonly configured as a system-assigned managed identity.

  • ✓

    Automation rules

    Why this is correct

    Automation rules define the conditions and triggers that initiate automated responses in Microsoft Sentinel. They evaluate events such as incident creation, alert generation, or severity changes and then invoke the appropriate playbook or perform direct actions like changing incident status. Automation rules are required because they provide the central, policy-driven logic that connects incoming security events to the correct playbook workflow, making automatic response possible without manual intervention.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.