SC-200 Manage a security operations environment Practice Question
Your incident response team uses Microsoft Sentinel. You need to automatically assign incidents to the appropriate analyst based on the incident category. What should you configure?
⚠ Common exam trap
Many exam-takers confuse analytics rules (which create incidents) with automation rules (which act on existing incidents), leading them to incorrectly select option B thinking the rule itself can assign ownership during incident creation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an automation rule that runs a playbook to assign the incident.
Automation rules in Microsoft Sentinel can trigger a playbook when an incident is created or updated. By configuring an automation rule with a condition based on the incident category, you can invoke a playbook that uses the Microsoft Sentinel API or Logic Apps to set the incident's owner field, thereby assigning it to the appropriate analyst. This is the correct approach because automation rules are designed to run automated responses, including playbooks, on incidents.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create an automation rule that runs a playbook to assign the incident.
Why this is correct
An automation rule can be configured to respond to incident creation or update events and launch a playbook built with Azure Logic Apps. The playbook uses the Microsoft Sentinel connector's update-incident action to set the owner (assigned-to) field, making it the correct native mechanism for programmatic ownership assignment.
- ✗
Create an analytics rule that sets the owner field.
Why it's wrong here
Analytics rules define the detection logic—scheduled queries, alert details, and entity mappings—that generate alerts and incidents; they have no schema for ownership or assignment. The owner property is incident metadata set after detection, so attempting to set it in an analytics rule is outside the rule's capabilities.
- ✗
Create a custom incident label for each category.
Why it's wrong here
Custom incident labels (e.g., Low, Medium, High urgency) are free-text or predefined tags stored on an incident for classification and filtering; they are purely descriptive metadata. Labels never change who owns the incident because ownership is stored separately in the Owner property, not in the label collection.
- ✗
Create a workbook that filters incidents by category.
Why it's wrong here
Workbooks render KQL queries as interactive visualizations (tables, charts, graphs) for analysis and reporting; they are read-only and cannot modify incident state. Filtering a workbook by category only changes the displayed data, leaving the owner field untouched and the incident unassigned.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.