SC-200 Manage a security operations environment Practice Question
Which TWO actions can be performed using Microsoft Sentinel automation rules? (Choose two.)
⚠ Common exam trap
A common mix-up: candidates confuse automation rules with playbooks or other Sentinel configuration tasks, assuming that any automated action (like deploying connectors or creating rules) can be done via automation rules, when in fact automation rules are strictly for incident management actions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Change the severity of an incident
Automation rules in Microsoft Sentinel allow you to automate incident management tasks, including changing the severity of an incident and adding tags. These actions are part of the incident-handling workflow and can be triggered when an incident is created or updated, enabling consistent triage and enrichment without manual intervention.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Change the severity of an incident
Why this is correct
Automation rules in Microsoft Sentinel include a built-in action that updates the incident severity field. This action can be triggered conditionally, for example when an incident is assigned a MITRE technique or when entity analytics raise the risk score. Because severity directly drives triage priority in the SOC queue, being able to auto-adjust it based on changing context is a core incident-response action, making this a correct answer.
- ✓
Add a tag to an incident
Why this is correct
Applying a custom tag to an incident is a native action available within Sentinel automation rules. Tags are arbitrary key/value labels that help categorize incidents for reporting, hunting, and workflow separation, such as marking high-value accounts or indicating a false-positive pattern. Automation rules can add tags when an incident matches a condition, which is a supported and commonly used incident-management capability, so this is correct.
- ✗
Deploy a data connector
Why it's wrong here
Deploying a data connector is an administrative provisioning task that occurs at the Sentinel workspace level, typically through the Content hub or the Data connectors blade. Automation rules, in contrast, operate exclusively on already-ingested alerts and incidents and have an action set limited to incident attributes, playbooks, and simple status changes. The action list for automation rules does not include any data-source integration or connector deployment options, so this action cannot be performed via an automation rule.
- ✗
Modify a watchlist
Why it's wrong here
Watchlist modifications, such as adding rows or editing entries, are performed through the Sentinel watchlist UI or via the Microsoft Graph API, not through automation rules. Automation rules are designed to react to incidents and alerts, and their available actions include only incident updates like severity, tags, owner, and playbook invocation—there is no watchlist CRUD action. While watchlists can inform analytics queries and automation logic, mutating them is outside the scope of rule-based incident automation, making this option incorrect.
- ✗
Create a scheduled query rule
Why it's wrong here
Scheduled query rules, which define recurring detection queries that generate alerts, are authored in the Analytics blade of Microsoft Sentinel and require configuration of query schedule, alert threshold, and entity mapping. Automation rules execute after an alert or incident is created and cannot create or alter those detection definitions. Since the action set of an automation rule is limited to post-detection response tasks, creating a scheduled query rule is not something an automation rule can perform, so this option is incorrect.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.