Courseiva

SC-200 Manage a security operations environment Practice Question

You are using Microsoft Sentinel to manage incidents. You want to automatically close incidents that are older than 90 days and have a status of 'New'. What is the most efficient way to achieve this?

⚠ Common exam trap

SC-200 often tests the distinction between automation rules (event-triggered) and playbooks (which can be schedule-triggered) — candidates incorrectly assume automation rules can handle time-based conditions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a playbook that runs on a schedule (e.g., daily) and closes incidents that meet the criteria.

A scheduled playbook is the most efficient way to automatically close stale incidents because Microsoft Sentinel playbooks (Logic Apps) support recurrence triggers that can query the Sentinel incidents API on a schedule, filter by status 'New' and createdTime older than 90 days, and close them in bulk. This is a native, low-code automation path that doesn't require manual intervention or modifying detection logic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a workbook that shows old incidents and manually close them.

    Why it's wrong here

    A workbook only displays data; it cannot close incidents, so an administrator must still act manually, which fails the automation requirement. Workbooks suit visual reporting and dashboards across Sentinel data, and would be the right pick if the goal were monitoring incident trends rather than enforcing a 90-day closure policy.

  • ✓

    Create a playbook that runs on a schedule (e.g., daily) and closes incidents that meet the criteria.

    Why this is correct

    A scheduled playbook uses a recurrence trigger to query Microsoft Sentinel for incidents older than 90 days with status New, then closes them automatically. This satisfies the bulk-closure requirement without manual triage, unlike automation rules, which trigger on incident creation rather than elapsed age.

  • ✗

    Modify the analytics rule to automatically close incidents after 90 days.

    Why it's wrong here

    Analytics rules generate incidents; they cannot close them, so no age-based closure occurs. Automation rules are the mechanism for incident lifecycle actions such as closing stale incidents, whereas analytics rules suit detection logic and alert creation.

  • ✗

    Create an automation rule that triggers on incident update and closes the incident if the created time is older than 90 days.

    Why it's wrong here

    Automation rules trigger on incident creation or update, not on elapsed time, so an incident untouched for 90 days never fires the rule. Automation rules suit immediate reactions such as assigning owners or tagging incidents on creation; scheduled recurring logic belongs in a playbook with a scheduled trigger.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.