SC-200 Manage a security operations environment Practice Question
You are a security operations analyst at a company that uses Microsoft Sentinel. You need to ensure that all incidents generated from Microsoft Defender for Cloud Apps are automatically assigned to the same SOC team. The team uses Microsoft Teams to collaborate. Which configuration should you implement?
⚠ Common exam trap
Watch out — candidates often assume a playbook or logic app is required for any custom action, but Microsoft Sentinel's automation rules can directly set the incident owner without additional orchestration.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an automation rule that sets the owner to the team entity.
Automation rules in Microsoft Sentinel can directly set the incident owner to a specific user or group (such as a SOC team) without requiring a playbook. This ensures all incidents from Microsoft Defender for Cloud Apps are automatically assigned to the designated team, streamlining ownership and collaboration via Microsoft Teams.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a playbook that assigns the incident to the team and configure an automation rule to run it.
Why it's wrong here
Although an automation rule can trigger a playbook, using a playbook solely to assign an incident is unnecessarily complex; automation rules natively support setting the Owner field directly without invoking Azure Logic Apps. Playbooks add execution latency, require additional licensing and runbook permissions, and can fail if the Logic App is disabled or lacks connectivity. The automation rule's built-in 'Assign owner' action is the efficient, first-party mechanism for this simple property update.
- ✓
Create an automation rule that sets the owner to the team entity.
Why this is correct
Correct: In Microsoft Sentinel, an automation rule's actions include 'Assign owner,' which can set the Owner to either a specific user or a Microsoft Entra ID team (group). This assignment occurs natively during the incident lifecycle (e.g., immediately after creation) with no external service or manual step required. Simply create a rule with a trigger such as 'When incident creation' and the action 'Assign owner' to the appropriate team entity.
- ✗
Configure the Microsoft Defender for Cloud Apps connector to assign incidents to the team.
Why it's wrong here
The Microsoft Defender for Cloud Apps (MDCA) connector is a data-plane integration that ingests alerts and generates Sentinel incidents; it does not expose any action to update incident properties. Assignment is a Sentinel workspace concept controlled by automation rules or manual user action, not by the source connector. Even if the connector triggers an incident, ownership remains unset until a Sentinel-native workflow (or user) assigns it.
- ✗
Use a logic app to automatically post incidents to a Teams channel and have the team claim them.
Why it's wrong here
A Logic App that posts to a Teams channel merely creates a chat notification; it does not update the incident's Owner/assigned-to field, so Sentinel still records no responsible party. The team must manually open the incident and claim it, which could cause duplicate work or missed incidents if the notification is overlooked. Unlike an automation rule's atomic 'Assign owner' action, this approach separates notification from assignment and leaves the assignment process unreliable.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.