SC-200 Manage a security operations environment Practice Question
You need to ensure that critical incidents in Microsoft Sentinel are automatically assigned to a senior security analyst. What should you configure?
⚠ Common exam trap
Candidates often confuse automation rules (which handle incident lifecycle actions like assignment) with analytics rules (which generate alerts), leading them to pick option A incorrectly.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an automation rule that assigns the incident to the analyst.
Automation rules in Microsoft Sentinel allow you to automatically assign incidents to specific users or groups based on conditions like severity or title. By creating an automation rule that triggers on incident creation and sets the owner to the senior security analyst, you ensure critical incidents are assigned without manual intervention.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create an analytics rule with a custom schedule.
Why it's wrong here
An analytics rule with a custom schedule is fundamentally a detection mechanism: it runs a KQL query at defined intervals and generates alerts that may later be aggregated into incidents. While you can control the query frequency and incident-creation settings, an analytics rule has no action that modifies an incident's owner or performs any workflow step. Therefore, it cannot guarantee that critical incidents are assigned to a specific analyst.
- ✗
Configure a workbook to filter incidents by owner.
Why it's wrong here
A workbook in Microsoft Sentinel is an interactive reporting surface that queries Log Analytics data and visualizes incident properties, including the owner field. It is strictly a read-only tool that can help you filter and review incidents by owner, but it cannot execute mutations on incidents or change their assignment. Consequently, configuring a workbook to filter by owner is useful for monitoring but does not automatically assign an incident to an analyst.
- ✗
Add the analyst to a watchlist used in analytics rules.
Why it's wrong here
Watchlists in Sentinel are static reference data collections, such as lists of IP addresses, hostnames, or usernames, which analytics rules can use for enrichment or correlation in KQL queries. Adding an analyst to a watchlist would simply make that name available for lookups; the watchlist itself has no execution logic and cannot modify incident properties. Because watchlists are passive data stores, they cannot perform the operational action of assigning an incident to an owner.
- ✓
Create an automation rule that assigns the incident to the analyst.
Why this is correct
Automation rules are the only one of these options that directly acts on incident properties after an incident is created or updated. You can configure a rule with conditions like 'incident title contains critical' and an action of 'Assign to analyst,' which automatically sets the owner field to the chosen analyst. This is the intended, supported mechanism in Microsoft Sentinel for ensuring critical incidents are owned by a specific person.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.