SC-200 Manage a security operations environment Practice Question
Which TWO actions can be performed using automation rules in Microsoft Sentinel? (Select TWO.)
⚠ Common exam trap
It's easy for candidates to confuse automation rules with analytics rules, mistakenly thinking automation rules can create incidents or modify analytics rule logic, when in fact automation rules only act on existing incidents and cannot alter detection logic or delete incidents.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Assign an incident to a specific owner.
Automation rules in Microsoft Sentinel can perform actions such as assigning an incident to a specific owner. This is a built-in action within the automation rule configuration, allowing you to automatically set the owner field of an incident based on conditions like severity or rule ID, without requiring a playbook.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a new incident from an alert.
Why it's wrong here
Incident creation is done by analytics rules, not automation rules.
- ✗
Modify the query of an existing analytics rule.
Why it's wrong here
Automation rules do not modify analytics rules.
- ✓
Assign an incident to a specific owner.
Why this is correct
Assignment is a supported action in automation rules.
- ✗
Delete an incident automatically.
Why it's wrong here
Automation rules cannot delete incidents.
- ✓
Trigger a playbook when an incident is created.
Why this is correct
Automation rules can trigger playbooks as an action.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 209-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.