SC-200 Manage a security operations environment Practice Question
Exhibit
Refer to the exhibit.
```json
{
"properties": {
"displayName": "Malware Alert Auto-Isolate",
"triggers": [
{
"type": "Incident",
"conditions": [
{
"condition": "AlertTitle",
"operator": "Contains",
"value": "Malware"
}
]
}
],
"actions": [
{
"type": "RunPlaybook",
"playbookName": "IsolateDevice"
}
]
}
}
```You are reviewing the automation rule configuration shown in the exhibit. What is the purpose of this rule?
⚠ Common exam trap
Test-takers frequently confuse 'run a playbook' with 'resolve' or 'close' incidents, or think the rule itself creates the playbook, when in fact the rule only triggers an existing playbook.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Run a playbook to isolate a device when an incident with 'Malware' in the alert title is created
The automation rule is configured to trigger when an incident is created with 'Malware' in the alert title. The action specified is to run a playbook, which in Microsoft Sentinel can perform complex remediation steps such as isolating a device. Option C correctly identifies this combination of trigger condition and action.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Automatically resolve incidents related to malware
Why it's wrong here
This rule is not performing a status change to 'Resolved' on incidents. In Microsoft Sentinel, an automation rule's action can change the incident status (for example, set to Active, New, or Closed), but the action configured here is 'Run playbook,' which invokes a Logic App workflow. Additionally, the rule's condition is narrowly scoped to alert titles containing 'Malware'—not all incidents that are merely 'related to malware'—so the wording overstates both the trigger scope and the action type.
- ✗
Automatically close incidents with 'Malware' in the title
Why it's wrong here
The rule does not have a 'Close incident' action; closing an incident requires changing its status to 'Closed' and typically supplying a classification and classification reason. The configured action is to execute a playbook, not to modify the incident state at all. Also, the condition is based on the alert title containing 'Malware' at incident creation time, not on the incident title itself, so 'incidents with Malware in the title' misstates the condition.
- ✓
Run a playbook to isolate a device when an incident with 'Malware' in the alert title is created
Why this is correct
This automation rule is triggered when a new incident is created and its condition matches alert titles containing the word 'Malware.' The rule's action invokes a playbook—an Azure Logic Apps workflow—that is designed to isolate the affected device, typically through a Microsoft Defender for Endpoint connector. This correctly describes the two core parts of the rule: the condition (incident created + alert title contains 'Malware') and the action (run a playbook to isolate a device).
- ✗
Create a playbook for malware alerts
Why it's wrong here
The automation rule does not create a Logic App or define a playbook; playbooks are authored separately in Azure Logic Apps and then referenced by an automation rule's 'Run playbook' action. Creating a playbook requires designing a workflow with connectors and triggers, which is outside the scope of the automation rule configuration shown. Thus, 'create a playbook' confuses the rule's execution action with the development of the automation artifact itself.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.