SC-200 Manage a security operations environment Practice Question
Which TWO actions can be performed using automation rules in Microsoft Sentinel?
⚠ Common exam trap
Candidates often confuse automation rules with analytics rules, mistakenly thinking automation rules can create or modify analytics rules, when in fact automation rules only react to incidents and perform actions like assignment or playbook execution.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Run a playbook
Automation rules in Microsoft Sentinel can trigger a playbook as an action when an incident is created or updated. Playbooks are automated workflows based on Azure Logic Apps, allowing for complex response actions such as threat containment, notification, or enrichment. This enables security teams to automate incident response without manual intervention.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Run a playbook
Why this is correct
Automation rules include a built-in 'Run playbook' action that invokes a Microsoft Sentinel playbook (an Azure Logic Apps workflow) automatically whenever the rule's trigger conditions are met, such as on incident creation or status change. This action allows security analysts to chain SOAR actions—like threat intelligence enrichment, quarantine, or email notification—directly from the incident workflow without manual intervention. The playbook must be registered with the incident trigger to appear in the automation rule.
- ✓
Assign an incident to an owner
Why this is correct
The 'Assign owner' action in an automation rule modifies the incident's Owner property to a designated user, email, or Microsoft Entra group, enabling automatic routing to the appropriate analyst or team based on severity, title, or entity classification. This is performed after incident creation/update, so rules can use conditions like 'If incident title contains ransomware' to hand it off. Assignment persists and is visible in incident details, and it does not require a playbook.
- ✗
Create an incident
Why it's wrong here
Incident creation is the responsibility of analytics rules—such as scheduled query rules, near-real-time rules, or Microsoft security data connectors—that convert alerts or query results into incidents. Automation rules execute after an incident already exists; they have no trigger or action that instantiates a brand-new incident record. Therefore, 'Create incident' is not a valid automation rule action, and automation cannot synthesize incidents outside analytic findings.
- ✗
Modify an analytics rule
Why it's wrong here
Automation rules work solely on incident-level attributes (owner, status, severity, tags, comments, and playbooks), not on the detection definitions that govern which alerts are generated. Modifying an analytics rule, such as changing its query, schedule, or alert suppression, is performed through the Analytics Rules blade or ARM/Azure Policy, not through an automation rule. Because automation rules lack write access to analytics rule configuration, this option is invalid.
- ✗
Delete an incident
Why it's wrong here
Microsoft Sentinel incidents are immutable audit records; there is no delete action exposed in automation rules or the incident interface. Automation rules can 'Close incident' with a chosen classification and comment, which is the approved way to end an incident's lifecycle. Deleting would destroy evidence and audit history, which Sentinel deliberately prevents to maintain security-investigation traceability.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.