Courseiva

SC-200 Manage a security operations environment Practice Question

You are a security operations analyst at a company that uses Microsoft Sentinel. You need to create an automation rule that automatically closes incidents with a severity of Informational and a status of New after 24 hours, but only if they do not contain any entities. Which three conditions must you configure in the automation rule?

⚠ Common exam trap

Candidates often confuse incident status values or severity levels, such as using Active instead of New or Low instead of Informational, which would misdirect the automation rule.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Severity equals Informational, Status equals New, and Entities count equals 0.

The automation rule must target incidents that are Informational severity, have a status of New, and contain no entities. These conditions ensure that only low-risk, unassigned incidents without any associated entities are automatically closed after 24 hours, reducing analyst workload. The other combinations either target incorrect severity, status, or entity presence, failing to meet the scenario's requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Severity equals Low, Status equals New, and Entities count equals 0.

    Why it's wrong here

    It uses Severity equals Low instead of Informational. Severity levels in Microsoft Sentinel include High, Medium, Low, and Informational. The scenario specifically requires Informational severity, so using Low would target the wrong incidents and fail to meet the requirement.

  • ✓

    Severity equals Informational, Status equals New, and Entities count equals 0.

    Why this is correct

    This option correctly identifies the three conditions required: severity equal to Informational, status equal to New, and no entities present. These conditions ensure that only low-priority incidents without entities are automatically closed after the specified time, aligning with the scenario's requirement to reduce noise from such incidents.

  • ✗

    Severity equals Informational, Status equals New, and Entities count greater than 0.

    Why it's wrong here

    It uses Entities count greater than 0. The scenario requires incidents with no entities. Using greater than 0 would select incidents that do contain entities, which is the opposite of what is needed, and would not automatically close the intended incidents.

  • ✗

    Severity equals Informational, Status equals Active, and Entities count equals 0.

    Why it's wrong here

    It uses Status equals Active instead of New. The scenario specifies incidents with a status of New. In Microsoft Sentinel, incident statuses include New, Active, and Closed. Using Active would not match the intended incidents, potentially leaving New incidents unclosed or affecting the wrong set.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.