SC-200 Manage a security operations environment Practice Question
You are managing a Microsoft Defender XDR environment. The security team wants to receive email notifications when a new incident is created with severity 'High' or 'Medium'. They also want to ensure that notifications are sent only for incidents that are not automatically resolved by AIR. What should you configure?
⚠ Common exam trap
Many candidates confuse Microsoft Sentinel's incident management (which uses automation rules and playbooks) with Microsoft Defender XDR's native incident notification system, leading candidates to select options that apply to Sentinel rather than Defender XDR.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an email notification rule in Microsoft Defender XDR with conditions for severity and status set to 'Active'.
Microsoft Defender XDR allows you to create email notification rules specifically for incidents, with conditions to filter by severity (e.g., High, Medium) and status (e.g., Active). This ensures notifications are sent only for new incidents that are not automatically resolved by AIR, as AIR-resolved incidents would have a status of 'Resolved' or 'Redirected', not 'Active'.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a playbook in Microsoft Sentinel that sends an email when an incident is created.
Why it's wrong here
A Microsoft Sentinel playbook uses Azure Logic Apps to automate incident response, and it can indeed send emails via an Office 365 Outlook connector. However, a Sentinel playbook is triggered by Sentinel incidents, not by native Microsoft Defender XDR incidents unless you have enabled the Defender XDR data connector and created a corresponding automation rule. Since the scenario explicitly states you are managing a Defender XDR environment, using Sentinel introduces an unnecessary dependency and does not leverage the built-in email notification rule available in the Microsoft 365 Defender portal. Moreover, this approach would not meet the requirement to directly notify on Defender XDR incident creation.
- ✗
Configure an automation rule in Microsoft Sentinel to send email notifications.
Why it's wrong here
Automation rules in Microsoft Sentinel are designed to manage the incident lifecycle inside the Sentinel workspace, such as changing status, assigning ownership, or triggering playbooks. They do not natively run against Microsoft Defender XDR incidents; Defender XDR incidents must first be streamed into Sentinel via the Microsoft 365 Defender connector, and even then the automation rule executes on the Sentinel representation of the incident, not the original Defender incident. The native, simpler solution is to create an email notification rule directly in Microsoft Defender XDR, which does not require Sentinel to be deployed or configured.
- ✓
Create an email notification rule in Microsoft Defender XDR with conditions for severity and status set to 'Active'.
Why this is correct
Email notification rules in Microsoft Defender XDR are the native mechanism for sending email alerts when incidents meet specific criteria, such as severity (high, medium) and status (New, Active, Resolved). To receive notifications for open investigations, you would set the status condition to 'Active' and select the desired severity levels, then specify the recipient address and notification frequency. This rule is managed directly in Microsoft 365 Defender portal under Settings > Microsoft 365 Defender > Email notifications > Incidents, making it the intended feature for this scenario. It operates independently of Microsoft Sentinel and covers the full scope of Defender XDR incidents.
- ✗
Configure alert service settings in the Microsoft 365 Defender portal to send emails for high and medium severity alerts.
Why it's wrong here
The Microsoft 365 Defender portal does include alert service settings for email notifications, but those are typically for service-specific alerts (for example, antivirus or endpoint alerts) rather than unified incident notifications. Selecting 'alert service settings' may lead you to configure notifications at the alert level instead of the incident level, which this scenario requires. The correct feature in Defender XDR is specifically called 'Email notification rules', and it allows you to filter by incident severity and incident status, which the alert service settings do not provide in the same manner. Thus, while this option seems similar, it does not use the precise native feature designed for incident email notifications.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.