SC-200 Respond to security incidents Practice Question
Your organization uses Microsoft Defender for Endpoint (MDE) and Microsoft Sentinel. You receive an alert in MDE about a suspicious PowerShell command executed on a device. You create an incident in Sentinel from this alert. You need to automatically collect a memory dump from the affected device for further analysis. You have a playbook that can initiate a memory dump collection via the MDE API. What is the best way to automate this?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an automation rule that triggers when an incident is created from a MDE alert and runs the playbook to collect the memory dump.
Automation rules in Microsoft Sentinel can trigger playbooks when an incident is created. Option B is correct because it creates an automation rule that triggers on incident creation from a Microsoft Defender for Endpoint alert and runs the playbook to collect the memory dump automatically. Option A is incorrect because alert details enrichment only adds enrichment details, it does not run playbooks. Option C is incorrect because entity behavior analytics does not directly trigger playbooks on incident creation. Option D is incorrect because the requirement is automation, not manual action.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure the alert details enrichment in Sentinel to automatically add the memory dump to the incident.
Why it's wrong here
Alert enrichment adds contextual data to the incident record; it cannot invoke the MDE API to collect a memory dump from the device. Enrichment suits adding threat intelligence or entity details to alerts, but the requirement is automated response action, which needs an automation rule triggering the playbook.
- ✓
Create an automation rule that triggers when an incident is created from a MDE alert and runs the playbook to collect the memory dump.
Why this is correct
Automation rules in Microsoft Sentinel respond to incident creation events, and can filter on the alert's product source being Microsoft Defender for Endpoint. Triggering the playbook this way runs the MDE API memory dump collection automatically, satisfying the requirement without manual intervention.
- ✗
Use entity behavior analytics in Sentinel to trigger the playbook when suspicious behavior is detected.
Why it's wrong here
Entity behaviour analytics baselines activity to surface anomalies; it does not evaluate incident entities or invoke playbooks, so it cannot trigger the memory-dump automation. It is tempting because UEBA also consumes MDE signals, but its output is behavioural insight, not incident-driven orchestration. The correct mechanism triggers on the Sentinel incident itself.
- ✗
Have the analyst manually run the playbook from the incident page.
Why it's wrong here
Manual execution requires an analyst to trigger the playbook, so collection is not automatic and depends on human availability, contradicting the automation requirement. It is tempting because running playbooks on demand suits ad-hoc investigation, but the stem demands automatic memory dump collection triggered by the incident.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.