Courseiva

SC-200 Manage a security operations environment Practice Question

Which TWO actions can be performed using automation rules in Microsoft Sentinel?

⚠ Common exam trap

Candidates often confuse automation rules with analytics rules, mistakenly thinking automation rules can create or modify analytics rules, when in fact automation rules only react to incidents and perform actions like assignment or playbook execution.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Run a playbook

Automation rules in Microsoft Sentinel can trigger a playbook as an action when an incident is created or updated. Playbooks are automated workflows based on Azure Logic Apps, allowing for complex response actions such as threat containment, notification, or enrichment. This enables security teams to automate incident response without manual intervention.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Run a playbook

    Why this is correct

    Automation rules include a built-in 'Run playbook' action that invokes a Microsoft Sentinel playbook (an Azure Logic Apps workflow) automatically whenever the rule's trigger conditions are met, such as on incident creation or status change. This action allows security analysts to chain SOAR actions—like threat intelligence enrichment, quarantine, or email notification—directly from the incident workflow without manual intervention. The playbook must be registered with the incident trigger to appear in the automation rule.

  • ✓

    Assign an incident to an owner

    Why this is correct

    The 'Assign owner' action in an automation rule modifies the incident's Owner property to a designated user, email, or Microsoft Entra group, enabling automatic routing to the appropriate analyst or team based on severity, title, or entity classification. This is performed after incident creation/update, so rules can use conditions like 'If incident title contains ransomware' to hand it off. Assignment persists and is visible in incident details, and it does not require a playbook.

  • ✗

    Create an incident

    Why it's wrong here

    Incident creation is the responsibility of analytics rules—such as scheduled query rules, near-real-time rules, or Microsoft security data connectors—that convert alerts or query results into incidents. Automation rules execute after an incident already exists; they have no trigger or action that instantiates a brand-new incident record. Therefore, 'Create incident' is not a valid automation rule action, and automation cannot synthesize incidents outside analytic findings.

  • ✗

    Modify an analytics rule

    Why it's wrong here

    Automation rules work solely on incident-level attributes (owner, status, severity, tags, comments, and playbooks), not on the detection definitions that govern which alerts are generated. Modifying an analytics rule, such as changing its query, schedule, or alert suppression, is performed through the Analytics Rules blade or ARM/Azure Policy, not through an automation rule. Because automation rules lack write access to analytics rule configuration, this option is invalid.

  • ✗

    Delete an incident

    Why it's wrong here

    Microsoft Sentinel incidents are immutable audit records; there is no delete action exposed in automation rules or the incident interface. Automation rules can 'Close incident' with a chosen classification and comment, which is the approved way to end an incident's lifecycle. Deleting would destroy evidence and audit history, which Sentinel deliberately prevents to maintain security-investigation traceability.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.