SC-200 Manage a security operations environment Practice Question
Exhibit
Refer to the exhibit.
```json
{
"properties": {
"displayName": "Block High-Risk User",
"triggers": [
{
"type": "MicrosoftSentinelIncident",
"incident": {
"severity": "High",
"status": "New"
}
}
],
"actions": [
{
"type": "RunPlaybook",
"playbook": {
"id": "/subscriptions/.../resourceGroups/.../providers/Microsoft.Logic/workflows/BlockUser"
}
}
]
}
}
```You have a Microsoft Sentinel automation rule as shown in the exhibit. The rule triggers a playbook that blocks a user in Microsoft Entra ID. The rule is enabled but never fires. What is the most likely reason?
⚠ Common exam trap
Test-takers frequently assume any playbook can be attached to an automation rule, but Microsoft Sentinel requires the playbook to have a specific Sentinel trigger to receive incident context; otherwise, the rule appears enabled but never executes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The playbook does not have a Microsoft Sentinel trigger.
The automation rule is configured to trigger a playbook, but for a playbook to be invoked by a Microsoft Sentinel automation rule, it must have a Microsoft Sentinel trigger (e.g., 'When a response to a Microsoft Sentinel incident is triggered'). Without this trigger, the playbook cannot receive the incident context from Sentinel, so the rule will never fire even if all other conditions are met.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The automation rule is disabled.
Why it's wrong here
The automation rule being disabled cannot be the cause because the scenario specifically states the rule is enabled. A disabled automation rule would not evaluate any incidents and would never invoke a playbook, but since it is enabled, its status is not the problem. The failure lies in the playbook's trigger configuration, not in the rule's enabled state.
- ✓
The playbook does not have a Microsoft Sentinel trigger.
Why this is correct
Automation rules in Microsoft Sentinel can only invoke a playbook if that playbook begins with a Microsoft Sentinel trigger, such as 'When a response to a Microsoft Sentinel alert is triggered' or 'When a Microsoft Sentinel incident is created'. Without this trigger, the playbook is not recognized as a valid Sentinel playbook and cannot be called by the automation rule. The rule may still run and match incidents, but the playbook action will fail or be unavailable because the expected trigger is missing.
- ✗
No incidents with High severity are created.
Why it's wrong here
The lack of High severity incidents is not the reason the playbook fails, because the scenario tells us that High severity incidents are being created. If no such incidents existed, the automation rule would simply not fire, but the playbook would still be correctly configured if it had the proper Sentinel trigger. Here, the issue is that the playbook is missing its required Sentinel trigger, so even when the rule fires on High severity incidents, the playbook cannot execute.
- ✗
The JSON syntax is invalid.
Why it's wrong here
The JSON syntax is not invalid, as the rule is displayed and enabled in the portal, implying it was accepted and saved successfully. A malformed JSON would prevent the automation rule from being created or stored correctly, which is not the case. The real problem is the playbook's missing Microsoft Sentinel trigger, which is a configuration issue at the Logic App level, unrelated to the rule's JSON representation.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.