Courseiva

SC-200 Manage a security operations environment Practice Question

Which TWO of the following are valid ways to automate incident response in Microsoft Sentinel?

⚠ Common exam trap

Many candidates confuse 'automation rule' with 'playbook' — an automation rule is the trigger condition, while a playbook is the action workflow; both are required for full automation, and the exam expects you to recognize that creating a playbook (A) and creating an automation rule that triggers a playbook (E) are the two valid steps in the process.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a playbook using Azure Logic Apps.

Azure Logic Apps is the native workflow engine for Microsoft Sentinel playbooks, allowing security analysts to automate incident response actions such as blocking IPs, resetting passwords, or enriching alerts. Playbooks are triggered by automation rules or directly from incidents, and they leverage hundreds of connectors to integrate with external systems. This is the primary and recommended method for building automated response workflows in Sentinel.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Create a playbook using Azure Logic Apps.

    Why this is correct

    Creating a playbook using Azure Logic Apps is a native Microsoft Sentinel automation capability because Sentinel playbooks are implemented as Logic Apps workflows, purpose-built to run automated response actions on incidents and alerts. These workflows can be invoked directly from an incident's context or via an automation rule without any custom code or external infrastructure, making it a valid automation method.

  • ✗

    Use Azure Functions to run a script.

    Why it's wrong here

    Using Azure Functions to run a script is not a native Sentinel automation mechanism; while Functions can technically call the Microsoft Graph Security API to modify incidents, doing so requires building and maintaining a custom connector or writing complex code against the API. Sentinel does not provide a built-in trigger or visual workflow binding for Azure Functions, so this approach falls outside the first-class automation options and introduces overhead for authentication and error handling.

  • ✗

    Use PowerShell to modify incidents via API.

    Why it's wrong here

    Using PowerShell to modify incidents via the API is not a native automation feature of Microsoft Sentinel; it involves running ad-hoc scripts from a local machine or external job scheduler rather than being integrated into the product's automation framework. Although the Sentinel REST API can be called from PowerShell, this approach lacks the managed, scalable execution lifecycle that built-in automation rules and playbooks provide, and it requires manual session management for authentication.

  • ✗

    Use Microsoft Power Automate to create a flow.

    Why it's wrong here

    Creating a flow with Microsoft Power Automate is not valid for Sentinel incident automation because Power Automate is a standalone workflow product with no native, prebuilt connector for Microsoft Sentinel incidents. Unlike Azure Logic Apps, which serves as the underlying platform for Sentinel playbooks, Power Automate cannot receive Sentinel's incident context directly, so it would require a custom intermediary to bridge the systems, making it not an integrated automation solution.

  • ✓

    Create an automation rule that triggers a playbook.

    Why this is correct

    Creating an automation rule that triggers a playbook is a standard native automation method in Microsoft Sentinel because automation rules are the platform's built-in mechanism for responding to incident creation, status changes, or alerts. These rules can invoke a Logic Apps-based playbook directly as an action, enabling immediate, rule-driven incident response without any custom code, and they support conditions, order, and scheduled execution.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

3 more ways this is tested on SC-200

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Which TWO features are available in Microsoft Sentinel to automate incident response?

easy
  • ✓ A.Playbooks based on Azure Logic Apps.
  • B.Workbooks.
  • C.Kusto Query Language (KQL) queries.
  • D.UEBA.
  • ✓ E.Automation rules.

Why A: Playbooks based on Azure Logic Apps (A) are the core automation mechanism in Microsoft Sentinel: they are Logic Apps workflows triggered by analytics rules or incidents that can run actions such as blocking an IP, posting to Teams, or opening a ticket, so they directly automate incident response. Automation rules (E) are also correct because they let you centrally manage and orchestrate incident handling — assigning owners, changing severity or status, tagging, and triggering playbooks — without writing code, which is exactly automation of incident response. Workbooks (B) are only for visualization and reporting dashboards, and KQL queries (C) are the query language used for hunting and analytics, not an automation feature. UEBA (D) provides behavioral analytics and entity insights to enrich detection, but it does not itself automate response actions.

Variation 2. Which THREE components are required to automate incident response in Microsoft Sentinel using playbooks? (Choose three.)

hard
  • ✓ A.An automation rule in Sentinel.
  • ✓ B.A Logic Apps workflow.
  • C.A workbook.
  • D.An analytics rule.
  • ✓ E.A trigger (e.g., when an incident is created).

Why A: Option A is correct because an automation rule in Microsoft Sentinel is the mechanism that binds a trigger condition (such as incident creation) to a playbook, enabling automatic execution of the response workflow. Option B is correct because playbooks in Microsoft Sentinel are built on Azure Logic Apps workflows, which contain the actual response actions (e.g., sending emails, blocking IPs, posting to Teams) that perform the automation. Option E is correct because a trigger, such as 'When an incident is created' or 'When an alert is created', is the required starting event that fires the Logic Apps workflow; without a trigger, the playbook cannot run automatically. Option C is not correct because a workbook is only a visualization and reporting tool in Sentinel and does not execute or automate response actions. Option D is not correct because an analytics rule detects threats and generates alerts/incidents, but it does not itself automate the response; it may be referenced by an automation rule, yet it is not a required component for the playbook automation itself.

Variation 3. You manage Microsoft Sentinel. You need to ensure that an automated response is triggered when a specific type of incident is created. The response should send an email to the on-call security engineer. What should you use?

easy
  • A.Use a watchlist to map incident types to email addresses and configure a scheduled query.
  • ✓ B.Create an automation rule that runs a playbook when an incident is created.
  • C.Modify the analytics rule to include an email action in the rule settings.
  • D.Create a workbook that alerts via email when new incidents appear.

Why B: Automation rules in Microsoft Sentinel can trigger a playbook (an Azure Logic Apps workflow) when an incident is created. The playbook can include an action to send an email to the on-call security engineer, providing the automated response required by the scenario.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.