SC-200 Manage a security operations environment Practice Question
You are a security operations analyst for a company that uses Microsoft Sentinel. The SOC manager wants to ensure that only incidents with a severity of High or Critical are automatically assigned to the on-call analyst, while all other incidents remain unassigned. You need to create an automation rule that meets this requirement. What should you do first?
⚠ Common exam trap
Test-takers frequently confuse automation rules with playbooks; automation rules are lightweight and built-in for incident management, while playbooks are more powerful but require Logic Apps and are better suited for complex orchestration.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a new automation rule and set the trigger to "When incident is created". Add a condition that checks if the incident severity is High or Critical. Then add an action to assign the incident to the on-call analyst.
Automation rules in Microsoft Sentinel are designed to automate incident handling tasks such as assignment, tagging, and status changes. They can be triggered when an incident is created and include conditions based on incident properties. This makes them the ideal solution for conditionally assigning incidents based on severity without custom development.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a playbook that runs on incident creation, parses the incident severity, and if High or Critical, assigns the incident using the Microsoft Sentinel API.
Why it's wrong here
While a playbook can perform assignment via the API, it introduces unnecessary complexity. Playbooks are Logic Apps and require additional configuration and permissions. The requirement is simple and can be met with a built-in automation rule, which is the recommended and more efficient method.
- ✗
Create a scheduled query rule that detects High and Critical incidents and then triggers a Logic App to assign them.
Why it's wrong here
Scheduled query rules are used to create alerts and incidents, not to manage existing incidents. Using a scheduled rule to detect already-created incidents would be inefficient and could create duplicate incidents. Automation rules are the correct tool for post-incident actions like assignment.
- ✓
Create a new automation rule and set the trigger to "When incident is created". Add a condition that checks if the incident severity is High or Critical. Then add an action to assign the incident to the on-call analyst.
Why this is correct
This approach uses the native automation rule capability in Microsoft Sentinel to evaluate incident severity at creation time and assign accordingly. Automation rules support conditions based on incident properties, including severity, and can perform assignment actions. This directly satisfies the requirement without custom logic or external components.
- ✗
Modify the incident settings in Microsoft Sentinel to automatically assign all High and Critical incidents to the on-call analyst by default.
Why it's wrong here
Microsoft Sentinel does not provide a global setting to automatically assign incidents based on severity. Assignment is typically handled through automation rules or playbooks. There is no native 'incident settings' option that performs this conditional assignment.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.