Courseiva

SC-200 Respond to security incidents Practice Question

Which THREE features in Microsoft Sentinel allow an analyst to automate incident response actions?

⚠ Common exam trap

Watch out — candidates often confuse Watchlists and Workbooks as active automation tools, when they are passive data stores and visualization tools, respectively, and fail to recognize that only Playbooks, Automation rules, and Analytics rules with incident automation can directly execute response actions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Playbooks (Logic Apps)

Playbooks (Logic Apps) are correct because they provide a library of pre-built or custom workflows that can be triggered by automation rules or analytics rules to execute complex, multi-step incident response actions, such as blocking IPs, isolating hosts, or enriching alerts with threat intelligence. They integrate with Azure services and third-party APIs via connectors, enabling automated remediation without manual intervention.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Playbooks (Logic Apps)

    Why this is correct

    Playbooks in Microsoft Sentinel are built on Azure Logic Apps and allow analysts to define complex, multi-step automated response workflows. They can connect to hundreds of external services, execute custom logic, and perform remediation actions such as blocking an IP, disabling a user, or opening a service desk ticket. Playbooks are the most flexible automation tool in Sentinel, often triggered by automation rules or directly from an incident, and are a correct answer for features that enable automated workflows.

  • ✗

    Watchlists

    Why it's wrong here

    Watchlists are local, tabular reference data that you can store in a Sentinel workspace and then use in analytics rules, searches, and detection queries. They exist solely to provide contextual data for correlation and enrichment, such as lists of high-value assets or compromised accounts. They do not contain any executable logic or actions, so they cannot automate an incident response process. Thus, watchlists are a data mechanism, not an automation feature.

  • ✗

    Workbooks

    Why it's wrong here

    Workbooks are interactive dashboards in Microsoft Sentinel that visualize data by running Azure Resource Manager templates and KQL queries. They help analysts monitor trends, investigate incidents, and present findings but only render information in a user interface. Workbooks have no built-in capability to trigger tasks, run scripts, or modify incidents, making them purely a reporting and analysis tool. Therefore, workbooks are incorrect when the requirement is to automate analyst actions.

  • ✓

    Automation rules

    Why this is correct

    Automation rules are native Microsoft Sentinel configurations that run in response to incident triggers, such as when an incident is created or updated, and can execute a set of predefined actions. These actions include changing the incident severity, assigning it to a user or group, adding comments or tags, and invoking a playbook for deeper automation. Automation rules offer a no-code method to standardize triage and escalation, so they are one of the three features that enable automation in Sentinel.

  • ✓

    Analytics rules with incident automation

    Why this is correct

    Analytics rules can be created with incident automation by configuring an automation rule or playbook in the 'Incident automation' tab of the rule wizard. When the analytics rule generates an incident, those automated actions are executed automatically, enabling immediate response without manual analyst intervention. This feature tightly couples threat detection with response actions, such as notifying a security team or triggering a playbook. Therefore, analytics rules with incident automation are another valid answer for automating responses in Sentinel.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

2 more ways this is tested on SC-200

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Your organization uses Microsoft Sentinel. You receive an alert for a suspicious sign-in from an unusual location. You want to automatically create an incident and assign it to the security team for investigation. What should you configure?

easy
  • A.Add the user to a watchlist and configure a fusion rule.
  • B.Create a playbook that triggers on the alert and creates an incident manually.
  • C.Modify the analytics rule to set the incident creation setting to 'Create incident from alert'.
  • ✓ D.Configure an automation rule that runs when the alert is generated, creates an incident, and sets the owner to the security team.

Why D: Automation rules in Microsoft Sentinel allow you to automatically create incidents from alerts and assign them to specific teams or owners. This is the native, efficient method to handle the scenario without manual intervention or custom playbooks.

Variation 2. Which Microsoft Sentinel feature allows you to automatically respond to incidents by running a playbook when an incident is created?

easy
  • A.Analytics rules
  • B.Playbooks
  • C.Watchlists
  • D.Workbooks
  • ✓ E.Automation rules

Why E: Automation rules in Microsoft Sentinel allow you to define automated responses to incidents, including running a playbook when an incident is created. They provide a centralized way to trigger actions based on incident properties such as severity, status, or specific tactics, without needing to embed automation logic directly in analytics rules.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.