SC-200 Manage a security operations environment Practice Question
Your organization has deployed Microsoft Sentinel and configured a workspace with data connectors for Microsoft 365 Defender, Azure Activity, and Office 365. You need to ensure that security incidents are automatically assigned to the appropriate analyst based on the incident type. What should you configure?
⚠ Common exam trap
It's easy for candidates to confuse automation rules with playbooks or think that Microsoft 365 Defender incident assignment rules can manage all Sentinel incidents, but automation rules are the correct native mechanism for incident assignment within Sentinel across all data connectors.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an automation rule that runs when an incident is created, with conditions on the incident title, and an action to assign the incident to a specific owner.
Automation rules in Microsoft Sentinel allow you to define conditions (e.g., incident title containing specific keywords) and actions (e.g., assign incident to a specific owner) that run automatically when an incident is created. This directly meets the requirement to assign incidents to the appropriate analyst based on incident type without manual intervention.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a playbook triggered by incident creation that assigns the incident to a user based on the incident title.
Why it's wrong here
A playbook is a Logic Apps-based workflow intended for orchestrating response actions, such as isolating a compromised device or sending a threat intelligence query. Although playbook actions can technically update an incident record, using one solely to assign ownership based on the title is inefficient: it introduces additional compute, requires Logic Apps permissions, and does not replace the native, low-latency 'Assign incident to owner' action that an automation rule provides. The correct mechanism for title-based assignment is an automation rule, making this option incorrect.
- ✗
Add a watchlist that maps incident types to analyst email addresses and configure a scheduled analytics rule.
Why it's wrong here
Watchlists are lightweight lookup tables used inside KQL queries to match or enrich data during query execution; they do not take incident-management actions like assigning an owner. A scheduled analytics rule simply runs a query on a schedule and creates incidents from the results, and it has no action block to modify the resulting incident's owner. At best, mapping analyst emails in a watchlist might let the query add an email as a custom property, but automated owner assignment still requires an automation rule, so this option is wrong.
- ✓
Create an automation rule that runs when an incident is created, with conditions on the incident title, and an action to assign the incident to a specific owner.
Why this is correct
Automation rules are the built-in incident orchestration mechanism in Microsoft Sentinel, and one can be configured to trigger whenever an incident is created. The rule can evaluate a condition on the incident's title, such as 'title contains phishing,' and then execute the 'Assign incident to owner' action, specifying an Microsoft Entra ID user or group as the owner. This happens natively without invoking external workflows, providing instant, deterministic assignment that matches the requirement exactly.
- ✗
Configure a Microsoft 365 Defender incident assignment rule in the Microsoft 365 Defender portal.
Why it's wrong here
Microsoft 365 Defender maintains its own incident management surface, and it does allow incidents to be manually assigned or automatically routed using its assignment rules. However, those assignment settings apply only to Defender-related incidents in the Microsoft 365 Defender portal; they do not affect, control, or sync into Microsoft Sentinel's incident pipeline, even when Sentinel is linked to Defender via the data connector. Since the organization's incidents are in Sentinel, an assignment rule configured in the Microsoft 365 Defender portal cannot perform the requested assignment, making this option incorrect.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.