Courseiva

SC-200 Manage a security operations environment Practice Question

Exhibit

Refer to the exhibit.
```json
{
  "properties": {
    "displayName": "Malware Alert Auto-Isolate",
    "triggers": [
      {
        "type": "Incident",
        "conditions": [
          {
            "condition": "AlertTitle",
            "operator": "Contains",
            "value": "Malware"
          }
        ]
      }
    ],
    "actions": [
      {
        "type": "RunPlaybook",
        "playbookName": "IsolateDevice"
      }
    ]
  }
}
```

You are reviewing the automation rule configuration shown in the exhibit. What is the purpose of this rule?

⚠ Common exam trap

Test-takers frequently confuse 'run a playbook' with 'resolve' or 'close' incidents, or think the rule itself creates the playbook, when in fact the rule only triggers an existing playbook.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Run a playbook to isolate a device when an incident with 'Malware' in the alert title is created

The automation rule is configured to trigger when an incident is created with 'Malware' in the alert title. The action specified is to run a playbook, which in Microsoft Sentinel can perform complex remediation steps such as isolating a device. Option C correctly identifies this combination of trigger condition and action.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Automatically resolve incidents related to malware

    Why it's wrong here

    This rule is not performing a status change to 'Resolved' on incidents. In Microsoft Sentinel, an automation rule's action can change the incident status (for example, set to Active, New, or Closed), but the action configured here is 'Run playbook,' which invokes a Logic App workflow. Additionally, the rule's condition is narrowly scoped to alert titles containing 'Malware'—not all incidents that are merely 'related to malware'—so the wording overstates both the trigger scope and the action type.

  • ✗

    Automatically close incidents with 'Malware' in the title

    Why it's wrong here

    The rule does not have a 'Close incident' action; closing an incident requires changing its status to 'Closed' and typically supplying a classification and classification reason. The configured action is to execute a playbook, not to modify the incident state at all. Also, the condition is based on the alert title containing 'Malware' at incident creation time, not on the incident title itself, so 'incidents with Malware in the title' misstates the condition.

  • ✓

    Run a playbook to isolate a device when an incident with 'Malware' in the alert title is created

    Why this is correct

    This automation rule is triggered when a new incident is created and its condition matches alert titles containing the word 'Malware.' The rule's action invokes a playbook—an Azure Logic Apps workflow—that is designed to isolate the affected device, typically through a Microsoft Defender for Endpoint connector. This correctly describes the two core parts of the rule: the condition (incident created + alert title contains 'Malware') and the action (run a playbook to isolate a device).

  • ✗

    Create a playbook for malware alerts

    Why it's wrong here

    The automation rule does not create a Logic App or define a playbook; playbooks are authored separately in Azure Logic Apps and then referenced by an automation rule's 'Run playbook' action. Creating a playbook requires designing a workflow with connectors and triggers, which is outside the scope of the automation rule configuration shown. Thus, 'create a playbook' confuses the rule's execution action with the development of the automation artifact itself.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.