Courseiva
Manage a security operations environmentmediumMultiple SelectObjective-mapped

SC-200 Manage a security operations environment Practice Question

Which TWO actions can be performed using automation rules in Microsoft Sentinel? (Select TWO.)

⚠ Common exam trap

It's easy for candidates to confuse automation rules with analytics rules, mistakenly thinking automation rules can create incidents or modify analytics rule logic, when in fact automation rules only act on existing incidents and cannot alter detection logic or delete incidents.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Assign an incident to a specific owner.

Automation rules in Microsoft Sentinel can perform actions such as assigning an incident to a specific owner. This is a built-in action within the automation rule configuration, allowing you to automatically set the owner field of an incident based on conditions like severity or rule ID, without requiring a playbook.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Create a new incident from an alert.

    Why it's wrong here

    Incident creation is done by analytics rules, not automation rules.

  • Modify the query of an existing analytics rule.

    Why it's wrong here

    Automation rules do not modify analytics rules.

  • Assign an incident to a specific owner.

    Why this is correct

    Assignment is a supported action in automation rules.

  • Delete an incident automatically.

    Why it's wrong here

    Automation rules cannot delete incidents.

  • Trigger a playbook when an incident is created.

    Why this is correct

    Automation rules can trigger playbooks as an action.

About these practice questions

This SC-200 question is part of Courseiva's 209-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.