Courseiva

SC-200 Manage a security operations environment Practice Question

Which TWO actions can you perform using Microsoft Sentinel automation rules? (Select two.)

⚠ Common exam trap

Test-takers frequently confuse automation rules with playbooks, assuming automation rules can directly send emails or create incidents, when in fact they only orchestrate actions that may be executed by playbooks or other components.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a task on an incident

Option A is correct because Microsoft Sentinel automation rules support the "Create task" action, which adds a task to an incident for analyst follow-up. Option B is correct because automation rules can trigger a playbook (Logic App) to run against an incident, which is one of their primary purposes. Option C is not correct because incident creation is handled by analytics rules, not automation rules. Option D is not correct because automation rules cannot create other automation rules. Option E is not correct because sending an email is done by a playbook, not directly by an automation rule action.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Create a task on an incident

    Why this is correct

    Automation rules in Microsoft Sentinel can add a task to an incident, letting the SOC track required follow-up actions; rules also support assignment, tagging, status changes and running playbooks, but task creation is a native incident action.

  • ✓

    Run a playbook on an incident

    Why this is correct

    Automation rules trigger a playbook when an incident is created, updated, or closed, satisfying the requirement to run a playbook on an incident. Unlike analytics rules, which generate incidents, automation rules orchestrate response by invoking a Logic App playbook scoped to that incident, enabling immediate containment without manual analyst intervention.

  • ✗

    Create an incident automatically

    Why it's wrong here

    Automation rules act on incidents that analytics rules have already generated; they cannot create incidents themselves. Incident creation is the job of an analytics rule matching log data. Automation rules only run after an incident exists, applying triage actions such as assignment, status changes, or playbook invocation.

  • ✗

    Create a new automation rule

    Why it's wrong here

    Automation rules cannot create further automation rules; they are themselves the rule objects, configured in the portal or via API. Rule creation is an administrative action, not a runtime action a rule performs. Automation rules instead trigger playbooks or modify incident properties when an alert is created.

  • ✗

    Send an email notification

    Why it's wrong here

    Automation rules cannot send email notifications directly; they have no native mail action. Notification delivery belongs to a playbook (Logic App) that the rule invokes, or to an alert's action group. The rule's own actions are limited to incident modification, assignment, tagging, and running playbooks.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.