Courseiva

SC-200 Manage a security operations environment Practice Question

You are a security operations analyst for a company that uses Microsoft Sentinel. You need to ensure that when an incident is created from a Microsoft Defender for Identity alert, the incident is automatically assigned to the 'Identity Protection' team and a specific tag 'Identity' is added. You have already created an automation rule that triggers on incident creation and has the condition 'Product name' contains 'Azure Advanced Threat Protection'. What should you do next to meet the requirement?

⚠ Common exam trap

The trap here is thinking that a playbook is needed for owner assignment and tagging, but automation rules natively support these actions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Add actions to the automation rule: 'Assign owner' with the Identity Protection team, and 'Add tags' with 'Identity'.

Automation rules in Microsoft Sentinel can perform multiple actions on incidents, including assigning an owner and adding tags. Since the automation rule already triggers on the correct incidents, adding these actions directly satisfies the requirement without the need for additional playbooks or manual intervention.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a playbook that uses the Microsoft Sentinel API to assign the incident and add tags, then attach it to the automation rule.

    Why it's wrong here

    While a playbook can perform these actions via the API, it is unnecessary because automation rules natively support owner assignment and tagging. Using a playbook adds complexity and potential failure points without benefit. The requirement can be met directly with automation rule actions.

  • ✓

    Add actions to the automation rule: 'Assign owner' with the Identity Protection team, and 'Add tags' with 'Identity'.

    Why this is correct

    Automation rules in Microsoft Sentinel support multiple actions, including assigning an owner and adding tags. By configuring these actions in the existing automation rule, you fulfill the requirement to automatically assign and tag incidents from Defender for Identity alerts. This is the most direct and efficient method.

  • ✗

    Use a workbook to monitor incidents and manually assign them to the Identity Protection team and add tags.

    Why it's wrong here

    Workbooks are for visualization and reporting, not for automated incident management. Manually assigning and tagging incidents does not meet the requirement for automatic actions and would be inefficient for a SOC. This approach lacks automation and consistency.

  • ✗

    Modify the analytics rule that generates the incident to include the assignment and tagging logic in its query.

    Why it's wrong here

    Analytics rules generate alerts and incidents but do not support assigning owners or adding tags as part of their configuration. These actions are handled by automation rules or playbooks. Modifying the analytics rule would not achieve the desired automatic assignment and tagging.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.