Courseiva

SC-200 Manage a security operations environment Practice Question

Which TWO actions can be performed using automation rules in Microsoft Sentinel? (Select TWO.)

⚠ Common exam trap

It's easy for candidates to confuse automation rules with analytics rules, mistakenly thinking automation rules can create incidents or modify analytics rule logic, when in fact automation rules only act on existing incidents and cannot alter detection logic or delete incidents.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Assign an incident to a specific owner.

Option C is correct because Microsoft Sentinel automation rules can perform incident management actions such as changing the owner, status, severity, or adding tags to an incident when their conditions are met. Option E is correct because automation rules can invoke a playbook (Logic App) in response to an incident being created, which is a core use case for orchestrating automated responses. Option A is not correct because incidents are generated from alerts by analytics rules, not by automation rules. Option B is not correct because automation rules cannot modify the query or logic of an existing analytics rule. Option D is not correct because automation rules do not support deleting incidents; they can close or change incident properties but not remove the incident record.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a new incident from an alert.

    Why it's wrong here

    Incidents are generated by analytics rules matching alerts, not by automation rules, which act on incidents already created. It is tempting because automation rules do run automatically on alerts, but their output is incident modification and playbook invocation, not incident creation.

  • ✗

    Modify the query of an existing analytics rule.

    Why it's wrong here

    Automation rules trigger playbooks and set incident properties such as severity, status, assignment and tags; they cannot edit an analytics rule's KQL query, which is changed in the rule itself. The confusion arises because both features live under the same Sentinel automation surface.

  • ✓

    Assign an incident to a specific owner.

    Why this is correct

    Automation rules run on incidents after creation and can assign an owner, change severity, add tags, or run a playbook. Assigning an incident to a specific owner is a supported action, letting triage routing happen automatically without manual analyst intervention.

  • ✗

    Delete an incident automatically.

    Why it's wrong here

    Automation rules can close an incident by setting its status, but deletion is not an available action; incidents are retained for auditing. The temptation comes from treating status changes as equivalent to removal, when only closure is offered.

  • ✓

    Trigger a playbook when an incident is created.

    Why this is correct

    Automation rules in Microsoft Sentinel can invoke a playbook as an action when an incident is created, satisfying the requirement to trigger automated response at incident generation. This differs from analytics rules, which generate incidents, and from playbooks themselves, which contain the response logic.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.