Courseiva

SC-200 Manage a security operations environment Practice Question

You are a security operations analyst for a company that uses Microsoft Sentinel. You have a playbook that remediates compromised user accounts by disabling the account and revoking sessions. You need to ensure that the playbook runs automatically whenever an incident is created with the 'Compromised User' tag. What should you configure?

⚠ Common exam trap

The trap here is thinking that a playbook's own trigger can filter by tags, when in fact automation rules provide that conditional logic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

An automation rule with a condition that checks for the 'Compromised User' tag and an action to run the playbook.

Automation rules are the mechanism in Microsoft Sentinel to automatically respond to incidents. By creating an automation rule that checks for the 'Compromised User' tag and then runs the playbook, you ensure the playbook executes only for incidents with that tag. This is the intended use of automation rules for playbook triggering.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    An automation rule with a condition that checks for the 'Compromised User' tag and an action to run the playbook.

    Why this is correct

    Automation rules in Microsoft Sentinel can trigger playbooks based on incident conditions, including tags. You can create a rule that evaluates the incident's tags and, if the 'Compromised User' tag is present, runs the specified playbook. This is the correct method to automatically execute a playbook when an incident with a specific tag is created. It provides the required automation without manual intervention.

  • ✗

    A playbook trigger configured in the Logic App Designer to start when a Sentinel incident is created.

    Why it's wrong here

    While a playbook (Logic App) can have a trigger for Microsoft Sentinel incident creation, that trigger alone does not filter by tags. The playbook would run for every incident, not just those with the 'Compromised User' tag. To achieve tag-based execution, you need an automation rule that evaluates the tag and then calls the playbook. Thus, this option lacks the necessary conditional logic.

  • ✗

    A scheduled analytics rule that runs every 5 minutes and triggers the playbook.

    Why it's wrong here

    Scheduled analytics rules are used to generate alerts and incidents based on log queries, but they cannot directly trigger playbooks. Playbooks are triggered by automation rules, not by analytics rules. While you could create an analytics rule that generates an incident with the tag, it would not automatically run the playbook. Therefore, this approach does not meet the requirement of automatic playbook execution upon incident creation.

  • ✗

    A Microsoft Sentinel workbook that monitors incidents with the 'Compromised User' tag and sends a command to run the playbook.

    Why it's wrong here

    Workbooks are for visualization and reporting, not for automation or triggering actions. They cannot execute playbooks. While you can use workbooks to monitor incidents, they do not provide the automation needed to run a playbook based on incident tags. Therefore, this option is incorrect for the stated requirement.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.