SC-200 Manage a security operations environment Practice Question
Which TWO steps are necessary to configure Microsoft Sentinel to automatically disable a compromised user account in Microsoft Entra ID when a high-severity incident is created?
⚠ Common exam trap
Candidates often confuse data connectors (which only ingest data) with playbooks (which perform actions), leading them to select options like the Microsoft Entra ID Protection data connector instead of the playbook and automation rule combination.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a playbook that uses the Microsoft Entra ID 'Disable user' action.
A playbook is an automated workflow that can contain the 'Disable user' action from Microsoft Entra ID, which directly disables a compromised user account. This action leverages the Microsoft Graph API to update the user's accountEnabled property to false, effectively blocking sign-ins. Without this playbook, there is no mechanism to execute the disablement action when an incident is created.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create a playbook that uses the Microsoft Entra ID 'Disable user' action.
Why this is correct
The playbook is the core remediation component because it contains the executable logic that calls the Microsoft Entra ID 'Disable user' action. This action, available via the Microsoft Entra ID connector in Azure Logic Apps, directly disables the targeted user account, effectively neutralizing the compromised identity. Without this action, the playbook would have no ability to apply a security control, so it is a mandatory piece of the automated response.
- ✓
Create an automation rule that triggers the playbook when a high-severity incident is created.
Why this is correct
An automation rule is required to connect a detected incident to the playbook. In Microsoft Sentinel, automation rules replace the older playbook triggers and can invoke a playbook automatically when an incident is created, provided conditions such as severity are met. Creating this rule ensures that high-severity incidents immediately start the disable-user playbook without manual analyst intervention, making it the essential orchestration step alongside the playbook itself.
- ✗
Enable the Microsoft Defender XDR connector.
Why it's wrong here
The Microsoft Defender XDR connector ingests alerts and incidents from Microsoft 365 Defender into Sentinel for centralized analysis. While this connector broadens visibility into cross-domain threats, it is not involved in the disable-user remediation workflow; the playbook uses the Microsoft Entra ID connector directly. Enabling this connector neither creates the playbook nor causes it to run on an incident, so it is irrelevant to the required configuration.
- ✗
Enable the Microsoft Entra ID Protection data connector.
Why it's wrong here
The Microsoft Entra ID Protection data connector brings risky user and sign-in events into Sentinel for analytic queries and detection rules. However, the playbook's 'Disable user' action relies on the Microsoft Entra ID API permissions, not on whether this data connector is enabled. Also, the automation rule triggers on incident creation and severity properties, not on raw connector data ingestion, so this connector is not a prerequisite for the automated disable action.
- ✗
Create an analytics rule that detects compromised user accounts.
Why it's wrong here
An analytics rule is designed to query ingested data and generate alerts or incidents when thresholds or patterns match, but it does not perform any remediation actions. In this scenario, the incident already exists—the automation rule reacts to its creation—so adding another analytics rule would be redundant and would not disable the user. The necessary steps are the playbook action for remediation and the automation rule for invocation, not a separate detection rule.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.