SC-200 Respond to security incidents Practice Question
Your organization has deployed Microsoft Sentinel and uses the Microsoft 365 connector to ingest audit logs. You receive an alert from Microsoft Defender for Office 365 about a phishing email that was delivered to a user's inbox. You need to create an incident in Sentinel and automatically quarantine the email. What is the most efficient way to achieve this?
⚠ Common exam trap
A common mix-up: candidates confuse 'custom analytics rules' (which generate alerts from raw data) with 'automation rules' (which react to existing alerts), leading them to choose Option B instead of C.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an automation rule in Microsoft Sentinel that is triggered when this specific alert is generated, and associate a playbook that uses the Microsoft 365 Defender connector to quarantine the email
Automation rules in Microsoft Sentinel can be triggered by specific alert generation (e.g., from Microsoft Defender for Office 365) and can execute a playbook. The playbook uses the Microsoft 365 Defender connector, which includes the 'Quarantine email' action, enabling automated quarantine without manual intervention. This is the most efficient method as it combines automatic incident creation with immediate remediation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use Microsoft Defender for Cloud Apps to investigate the alert and manually quarantine the email
Why it's wrong here
While Microsoft Defender for Cloud Apps provides investigation tools and can perform remediation actions, manually quarantining the email does not satisfy the requirement for an automated response. In a Sentinel deployment, automated responses should be orchestrated through automation rules and playbooks, not through manual console actions. Additionally, the Microsoft 365 Defender connector is specifically designed to send quarantine commands, whereas Defender for Cloud Apps would require separate configuration and still rely on human intervention.
- ✗
Create a custom analytics rule that triggers when an alert is generated, and configure the rule to run a playbook that quarantines the email
Why it's wrong here
Analytics rules are designed to create alerts from raw data, not to act upon alerts that already exist. Creating a custom analytics rule to detect the same signal would duplicate the existing Microsoft 365 Defender alert and add latency, and it still does not replace the need for an automation rule to invoke the playbook. Microsoft Sentinel's automation rules support an alert trigger that can directly run a playbook when the built-in alert fires, so a custom analytics rule is both unnecessary and architecturally incorrect.
- ✓
Create an automation rule in Microsoft Sentinel that is triggered when this specific alert is generated, and associate a playbook that uses the Microsoft 365 Defender connector to quarantine the email
Why this is correct
The correct approach is to create an automation rule in Microsoft Sentinel that triggers when the specific alert from Microsoft 365 Defender is generated. In the automation rule, you associate a playbook that uses the Microsoft 365 Defender connector to quarantine the email. This enables an automated, immediate response without human intervention, leveraging the built-in alert as the trigger and the Logic Apps playbook to execute the quarantine action.
- ✗
Manually create an incident in Microsoft Sentinel and then run a playbook to quarantine the email
Why it's wrong here
Manually creating an incident defeats the purpose of automation, as the alert should automatically generate an incident in Sentinel. This approach also requires a security analyst to notice the alert, create the incident, and then manually launch the playbook, which introduces delay and human error. The scenario specifically requires an automated response, so the playbook should be triggered automatically by an automation rule when the alert is generated.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.