Courseiva

SC-200 Manage a security operations environment Practice Question

You are managing a Microsoft Sentinel environment. You need to ensure that incidents are automatically assigned to the appropriate analyst based on the type of attack. The assignment must consider the current workload of each analyst. What should you use?

⚠ Common exam trap

Watch out — candidates often confuse static assignment (Option A or C) with dynamic assignment, failing to realize that only a playbook can query real-time workload data and make a runtime decision based on it.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use an automation rule with a playbook that queries the current incident assignments and assigns to the least busy analyst.

Automation rules in Microsoft Sentinel can trigger a playbook (Azure Logic App) that queries the current incident assignments and assigns the incident to the analyst with the fewest active incidents. This satisfies both the attack-type mapping (via the analytics rule that generates the incident) and the workload-balancing requirement, as the playbook can dynamically evaluate workload using Azure Resource Graph or Sentinel's API.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure multiple analytics rules, each with a different incident owner.

    Why it's wrong here

    Analytics rules are responsible for detection logic, not incident ownership. When an incident is generated from an alert, its owner field is not populated by the detection rule; it defaults to 'Automated' or remains unassigned. Configuring multiple rules with different supposed owners cannot achieve dynamic assignment because owner assignment is a post-detection action. Ownership changes must be performed by an automation rule or manually.

  • ✓

    Use an automation rule with a playbook that queries the current incident assignments and assigns to the least busy analyst.

    Why this is correct

    An automation rule can be triggered on incident creation and invoke a playbook built in Azure Logic Apps. The playbook queries the Microsoft Sentinel API (security insights 'Incident' resource) to retrieve all active incidents, counts the open assignments per analyst, determines the analyst with the fewest open incidents, and then updates the incident owner using an action such as 'Entity Incident Management' or an HTTP call to the API. This provides dynamic, workload-aware assignment that static configuration cannot.

  • ✗

    Create a watchlist that maps attack types to analyst names and use it in an analytics rule.

    Why it's wrong here

    A watchlist is a static CSV table used for joining, filtering, or enriching analytics rule queries; it cannot set the incident owner. Even if a watchlist maps an attack type to an analyst name, the analytics rule output schema has no field for owner and cannot alter the incident's owner property. This approach would only help detection logic, not the post-incident assignment required by the scenario.

  • ✗

    Create a workbook that shows analyst workload and manually assign.

    Why it's wrong here

    Workbooks are rich visualization tools built on Azure Monitor and Sentinel data, used for dashboards and analysis. While a workbook could display open incident buckets per analyst, it is non-interactive in terms of backend changes and cannot write an owner back to an incident. Any manual assignment based on that report still requires a user to update the incident, so it does not meet a requirement for automated least-busy assignment.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.