SC-200 Manage a security operations environment Practice Question
Which TWO actions can be performed using Microsoft Sentinel automation rules? (Select TWO.)
⚠ Common exam trap
Candidates often confuse automation rules with playbooks or analytics rules, assuming automation rules can create or modify detection logic, when in fact they are strictly for incident response and management actions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Assign an incident to a specific SOC analyst
Automation rules in Microsoft Sentinel allow you to automate incident management tasks, such as assigning incidents to specific SOC analysts based on criteria like severity or type. This is a core capability of automation rules, which can set the owner of an incident to a specific user or group, enabling efficient triage and accountability.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Assign an incident to a specific SOC analyst
Why this is correct
Within Microsoft Sentinel, an incident can be assigned to a specific SOC analyst either manually through the incident details pane or automatically via an automation rule action that sets the incident owner. Automation rules use conditions like severity or entity to route ownership to a chosen user or group, ensuring immediate accountability. This action is one of the incident-management capabilities that make Sentinel a central SOC workspace.
- ✗
Modify a data connector's configuration
Why it's wrong here
Modifying a data connector's configuration is not an action performed by Sentinel's automation rules; it is done in the Content management > Data connectors blade, where you select the connector and change workspace settings, log retention, or polling intervals. Automation rules operate exclusively on incidents and cannot alter the underlying data ingestion pipeline. This distinction is key: connectors are configured before data flows, and rule-based automation occurs after detection.
- ✗
Create a new analytics rule
Why it's wrong here
Creating a new analytics rule is performed from the Analytics blade or via ARM templates and Sentinel APIs, not through automation rules. Analytics rules define the detection logic that generates incidents, whereas automation rules apply post-detection actions to those incidents. An automation rule can respond to a particular analytics rule's results, but it cannot author or modify the analytics rule itself.
- ✗
Create a new watchlist
Why it's wrong here
Watchlists are created and managed in the Watchlists blade or via the Microsoft Sentinel API, where you upload a CSV file or use a KQL query to define a custom threat-intelligence table. Automation rules do not create watchlists; they may only reference watchlist data in incident conditions or as part of a playbook's logic. This separation ensures data sources remain distinct from operational automation.
- ✓
Run a playbook on an incident
Why this is correct
Microsoft Sentinel automation rules can run a playbook as one of their actions, either immediately when an incident is created or when it is updated. Playbooks are built on Azure Logic Apps and contain a series of steps, such as isolating a machine or sending a Teams message, providing a powerful response mechanism. This is a core automation rule capability, often used with trigger-based playbooks to reduce manual response time.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.