Courseiva

SC-200 Manage a security operations environment Practice Question

Which TWO of the following are valid actions that can be performed by an automation rule in Microsoft Sentinel? (Select two.)

⚠ Common exam trap

A common mix-up: candidates confuse automation rule actions with other Sentinel capabilities, such as thinking automation rules can modify analytics rules or manage watchlists, when in fact those are separate administrative functions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Assign incident to an analyst

Automation rules in Microsoft Sentinel can assign incidents to specific analysts or groups as part of incident response workflows. This action helps ensure accountability and proper triage by routing incidents to the appropriate personnel based on criteria like severity or type.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Delete a watchlist

    Why it's wrong here

    Automation rules in Microsoft Sentinel act only on incidents and their immediate properties; they cannot delete or otherwise manage watchlist entities, which are independent CSV-based threat-intelligence data stores governed through the Watchlist blade or the Microsoft Sentinel API. Removing a watchlist is a data-plane administrative operation, not an incident-response action, so no automation-rule action can perform it.

  • ✗

    Create a task

    Why it's wrong here

    Automation rules do not create tasks. Incident tasks, if used, are created through the incident tasks UI or via Graph API/other connectors; the standard automation rule action set does not include task creation. Although rules can change status, assign ownership, add comments, or run playbooks, adding a new task object is outside the current rule schema.

  • ✗

    Modify an analytics rule

    Why it's wrong here

    Modifying an analytics rule is outside the scope of automation-rule actions because automation rules are triggered by incidents and are not permitted to alter the underlying detection logic that generated the incident. Analytics rule changes—like changing query schedules or entity mappings—must be made in the Analytics blade or through ARM/API, not as an incident-remediation step. This is fundamentally a control-plane operation rather than an incident-action.

  • ✓

    Assign incident to an analyst

    Why this is correct

    Automation rules can assign an incident to an analyst by updating its owner field, typically using a property like Owner and a user principal name or object ID. This is a native action that helps route ownership immediately when an incident is created or when a condition such as severity is met, and it requires the same permissions as other incident updates. It is a valid action because it directly changes an incident property rather than a separate resource.

  • ✓

    Run a playbook

    Why this is correct

    Automation rules can trigger playbooks, which are Azure Logic Apps workflows, as the final or intermediate action in a rule's action list. This allows orchestration tasks such as enrichment, investigation, or containment to run automatically when an incident matches the rule's triggers and conditions. Playbook invocation is a native automation-rule action, and unlike watchlist deletion or task creation, it is explicitly designed to extend incident response beyond simple property edits.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.