SC-200 Manage a security operations environment Practice Question
Your organization uses Microsoft Defender for Endpoint (MDE) and Microsoft Sentinel. You have configured the Microsoft Defender for Endpoint connector in Sentinel to ingest alerts and incidents. The security team wants to automatically create a Sentinel incident when an MDE alert of severity 'High' or 'Critical' is generated. Additionally, they want to assign the incident to a specific SOC tier based on the alert title. For example, if the alert title contains 'Ransomware', assign to Tier 3; otherwise assign to Tier 2. You need to implement this automation efficiently. You have already enabled the connector and verified that MDE alerts are flowing into Sentinel. What is the best approach?
⚠ Common exam trap
SC-200 often tests the boundary between automation rules and playbooks — candidates assume automation rules can do conditional string parsing or run KQL, but only playbooks (Logic Apps) can execute that kind of branching logic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an automation rule that triggers on incident creation for High and Critical severity. The rule runs a playbook that uses Logic Apps to parse the alert title and assign the incident to the appropriate tier using the Microsoft Sentinel connector 'Update incident' action.
The requirement is conditional logic based on alert title ('Ransomware' → Tier 3, otherwise Tier 2), which cannot be expressed with simple automation-rule conditions alone. An automation rule can trigger on incident creation and filter by severity, then invoke a playbook; the playbook (Logic Apps) can parse the alert title and use the Microsoft Sentinel 'Update incident' action to set the owner to the correct tier. This combines Sentinel's native automation rule engine with Logic Apps' flexible conditional branching.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create an automation rule that triggers when an incident is created with a condition on alert severity, and set the owner to the appropriate group. Then create another automation rule for 'Ransomware' alerts.
Why it's wrong here
Two automation rules cannot both set the owner reliably: the severity rule fires first and assigns Tier 2, and Sentinel does not re-evaluate ownership when the second rule matches 'Ransomware'. A single rule with an OR condition on alert title handles both branches. Multiple rules suit independent, non-overlapping actions.
- ✗
Configure an automation rule with a condition on the alert title using KQL, then set the owner.
Why it's wrong here
Automation rule conditions support only property-based matching on incident and entity fields; they cannot evaluate KQL queries against alert titles. KQL belongs in analytics rules or workbooks. Automation rules are correct when conditions reference static incident properties such as severity, status or title text equality.
- ✓
Create an automation rule that triggers on incident creation for High and Critical severity. The rule runs a playbook that uses Logic Apps to parse the alert title and assign the incident to the appropriate tier using the Microsoft Sentinel connector 'Update incident' action.
Why this is correct
An automation rule fires on incident creation filtered to High and Critical severity, then invokes a playbook whose Logic Apps condition parses the alert title and assigns the tier via the Update incident action, meeting both routing requirements.
- ✗
Modify the Microsoft Defender for Endpoint analytics rule to include a custom mapping that assigns the incident to a specific owner based on the alert title.
Why it's wrong here
Analytics rules generate alerts; they cannot assign incident owners by alert title, so the tiering requirement goes unmet. Custom mappings only project entity fields into the alert schema. Analytics rules are the right tool when you need scheduled KQL detection logic producing alerts, not incident routing.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.