Courseiva

SC-200 Manage a security operations environment Practice Question

Exhibit

Refer to the exhibit.

{
  "type": "Microsoft.SecurityInsights/automationRules",
  "apiVersion": "2023-02-01-preview",
  "properties": {
    "displayName": "Auto-assign critical incidents",
    "order": 1,
    "triggeringLogic": {
      "triggersOn": "Incidents",
      "triggersWhen": "Created",
      "conditions": [
        {
          "property": "Severity",
          "operator": "Equals",
          "value": "High"
        }
      ]
    },
    "actions": [
      {
        "order": 1,
        "actionType": "ModifyProperties",
        "actionConfiguration": {
          "severity": "Medium",
          "owner": {
            "assignedTo": "SOC-Tier2"
          }
        }
      }
    ]
  }
}

You are reviewing an automation rule ARM template for Microsoft Sentinel. What is the result of deploying this automation rule?

⚠ Common exam trap

The trap here is that candidates may misinterpret the trigger condition as 'on update' (option B) or overlook the severity change action (option D), focusing only on the assignment part of the rule.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

When a High severity incident is created, the rule changes its severity to Medium and assigns it to SOC-Tier2.

The ARM template defines an automation rule that triggers when an incident is created with a severity of High. The rule's actions change the severity to Medium and assign the incident to the SOC-Tier2 owner. This matches option C exactly.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The rule assigns the incident to SOC-Tier2 only if the severity is Medium.

    Why it's wrong here

    The rule's gate is being mischaracterized as an internal conditional check for Medium severity. In the ARM template, the trigger condition is 'Incident severity equals High' at creation time, and the assignment to SOC-Tier2 executes immediately afterward with no additional Medium-severity condition. Medium-severity incidents never invoke the rule, so assigning 'only if' Medium is factually incompatible with the defined trigger.

  • ✗

    The rule triggers when an incident is updated and resets the severity to High.

    Why it's wrong here

    The trigger event and the severity action direction are both misstated. This rule is bound to a 'When incident is created' trigger, so update operations on an existing incident do not invoke it. Additionally, the action array updates severity to Medium, not High; the rule downgrades High-severity incidents, it never resets severity upward.

  • ✓

    When a High severity incident is created, the rule changes its severity to Medium and assigns it to SOC-Tier2.

    Why this is correct

    This option accurately reflects the ARM template's trigger and action configuration. On incident creation, when 'Severity' equals 'High', the rule executes an update action changing severity to 'Medium' and an assignment action setting the owner to the 'SOC-Tier2' group. Both actions run in sequence as part of that single rule instance, and no other conditions modify this behavior.

  • ✗

    The rule triggers when a High severity incident is created but does not change the severity.

    Why it's wrong here

    The trigger identification is correct, but the claim that severity remains untouched is contradicted by the action list. The template includes an 'Update incident' action that explicitly sets the severity field to 'Medium', so the rule does change severity. If severity were left alone, there would be no such action, but here the downgrade to Medium is a deliberate part of the workflow.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.