Courseiva

SC-200 Manage a security operations environment Practice Question

You are a SOC analyst investigating a high-severity incident. The incident involves a user who received a phishing email and clicked a link. Microsoft Defender for Office 365 detected the email as phishing and blocked the URL at time of click, but a follow-up investigation reveals that the user's mailbox has suspicious forwarding rules. You need to ensure that similar incidents are automatically remediated in the future. What should you configure in Microsoft Sentinel?

⚠ Common exam trap

Many candidates confuse the detection capability of analytics rules (Option B) with the remediation capability of automation rules and playbooks, assuming that analytics rules can directly perform actions like removing rules, when in fact they only generate alerts.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create an automation rule that triggers a playbook to remove the forwarding rule when an incident with the 'Phishing' tactic is created.

Microsoft Sentinel automation rules can trigger a playbook (an Azure Logic Apps workflow) when an incident is created with a specific tactic, such as 'Phishing'. This allows automatic remediation of suspicious forwarding rules without manual intervention, ensuring similar incidents are handled consistently.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure entity behavior analytics to automatically block the user.

    Why it's wrong here

    Microsoft Sentinel's entity behavior analytics (UEBA) provides anomaly detection and enriches entity insights, but it is a detection and correlation feature—it has no native capability to execute actions like blocking a user. Blocking, whether in Microsoft Entra ID or another security product, requires an integration such as a playbook or a conditional access policy triggered by an automation rule. Simply configuring UEBA to 'automatically block' is not supported; UEBA surfaces risk but leaves response orchestration to other components.

  • ✗

    Create an analytics rule that detects suspicious forwarding rules and automatically removes them.

    Why it's wrong here

    A scheduled analytics rule in Microsoft Sentinel runs KQL queries, and when a result matches, it creates an alert or incident; that is the end of its job. The rule does not have the inherent ability to perform actions such as removing a forwarding rule, because remediation actions require a Logic Apps-based playbook invoked by an automation rule. While you might build the rule to detect suspicious forwarding rules, the removal step must be defined in a playbook and associated with an automation rule—the analytics rule alone can never satisfy the 'automatically removes them' requirement.

  • ✓

    Create an automation rule that triggers a playbook to remove the forwarding rule when an incident with the 'Phishing' tactic is created.

    Why this is correct

    This is the correct approach because automation rules in Microsoft Sentinel are specifically designed to run when an incident is created (or updated), and they can trigger a playbook as a remediation action. The automation rule can match incidents with the 'Phishing' tactic and logically invoke a playbook that, for example, connects to Exchange Online PowerShell to remove the suspicious forwarding rule. This separation of concerns—analytics rule detects, automation rule orchestrates, playbook executes—is exactly how automated remediation should be implemented in Microsoft Sentinel.

  • ✗

    Add the user to a watchlist that triggers an automated investigation.

    Why it's wrong here

    A watchlist in Microsoft Sentinel is a static, user-managed list of entities used primarily for correlation and query-time joins inside analytics rules; it does not have an event-based trigger mechanism. Adding the user to a watchlist will not by itself initiate an automated investigation or any other action. To act on the watchlist, you would need to reference it from an analytics rule or playbook, which means the watchlist is only a data source, not a response component.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.