SC-200 Manage a security operations environment Practice Question
You are a security operations analyst for a company that uses Microsoft Sentinel. The SOC manager wants to reduce alert fatigue by automatically closing incidents that are known false positives. The incidents are created from a custom analytics rule that generates a specific alert name, 'Suspicious PowerShell Download'. You need to create an automation rule that automatically closes these incidents with a classification of 'BenignPositive'. What should you do?
⚠ Common exam trap
The trap here is assuming that playbooks are required for incident closure, but automation rules can directly close incidents without a playbook.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an automation rule with the condition 'Alert name' contains 'Suspicious PowerShell Download', and set the action to 'Close incident' with classification 'BenignPositive'.
Automation rules in Microsoft Sentinel are designed to automate incident handling tasks such as assignment, status changes, and classification. By creating an automation rule that triggers on incident creation and uses a condition based on the alert name, you can automatically close incidents with the desired classification. This is the most efficient and native method to achieve the SOC manager's objective.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use a workbook to monitor incidents with that alert name and manually close them in bulk.
Why it's wrong here
Workbooks are for visualization and reporting, not for automated actions. Manually closing incidents in bulk is not automated and does not scale, contradicting the goal of reducing alert fatigue through automation. This method also lacks the ability to apply a consistent classification automatically.
- ✗
Modify the analytics rule to set the incident severity to 'Informational' and enable automatic closure after 24 hours.
Why it's wrong here
Changing severity to Informational does not automatically close incidents, and Microsoft Sentinel does not have a built-in auto-closure after a time period. This approach would still require manual closure and does not classify incidents as BenignPositive, failing to meet the requirement.
- ✓
Create an automation rule with the condition 'Alert name' contains 'Suspicious PowerShell Download', and set the action to 'Close incident' with classification 'BenignPositive'.
Why this is correct
Automation rules in Microsoft Sentinel can trigger on incident creation and evaluate conditions such as alert name. Setting the action to close the incident with a specific classification directly addresses the requirement to auto-close known false positives. This reduces manual effort and ensures consistent handling of these incidents, aligning with the SOC manager's goal.
- ✗
Create a playbook that uses the 'Close incident' action and attach it to the analytics rule that generates the alert.
Why it's wrong here
While playbooks can close incidents, they are triggered by automation rules or analytics rules, but the 'Close incident' action in a playbook requires specifying the incident ARM ID and does not automatically apply a classification. Moreover, attaching a playbook directly to an analytics rule is not the standard method for automated incident closure based on alert name.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.