Courseiva

SC-200 Manage a security operations environment Practice Question

Your organization uses Microsoft Defender for Endpoint (MDE) and Microsoft Sentinel. You have configured the Microsoft Defender for Endpoint connector in Sentinel to ingest alerts and incidents. The security team wants to automatically create a Sentinel incident when an MDE alert of severity 'High' or 'Critical' is generated. Additionally, they want to assign the incident to a specific SOC tier based on the alert title. For example, if the alert title contains 'Ransomware', assign to Tier 3; otherwise assign to Tier 2. You need to implement this automation efficiently. You have already enabled the connector and verified that MDE alerts are flowing into Sentinel. What is the best approach?

⚠ Common exam trap

SC-200 often tests the boundary between automation rules and playbooks — candidates assume automation rules can do conditional string parsing or run KQL, but only playbooks (Logic Apps) can execute that kind of branching logic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create an automation rule that triggers on incident creation for High and Critical severity. The rule runs a playbook that uses Logic Apps to parse the alert title and assign the incident to the appropriate tier using the Microsoft Sentinel connector 'Update incident' action.

The requirement is conditional logic based on alert title ('Ransomware' → Tier 3, otherwise Tier 2), which cannot be expressed with simple automation-rule conditions alone. An automation rule can trigger on incident creation and filter by severity, then invoke a playbook; the playbook (Logic Apps) can parse the alert title and use the Microsoft Sentinel 'Update incident' action to set the owner to the correct tier. This combines Sentinel's native automation rule engine with Logic Apps' flexible conditional branching.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create an automation rule that triggers when an incident is created with a condition on alert severity, and set the owner to the appropriate group. Then create another automation rule for 'Ransomware' alerts.

    Why it's wrong here

    Two automation rules cannot both set the owner reliably: the severity rule fires first and assigns Tier 2, and Sentinel does not re-evaluate ownership when the second rule matches 'Ransomware'. A single rule with an OR condition on alert title handles both branches. Multiple rules suit independent, non-overlapping actions.

  • ✗

    Configure an automation rule with a condition on the alert title using KQL, then set the owner.

    Why it's wrong here

    Automation rule conditions support only property-based matching on incident and entity fields; they cannot evaluate KQL queries against alert titles. KQL belongs in analytics rules or workbooks. Automation rules are correct when conditions reference static incident properties such as severity, status or title text equality.

  • ✓

    Create an automation rule that triggers on incident creation for High and Critical severity. The rule runs a playbook that uses Logic Apps to parse the alert title and assign the incident to the appropriate tier using the Microsoft Sentinel connector 'Update incident' action.

    Why this is correct

    An automation rule fires on incident creation filtered to High and Critical severity, then invokes a playbook whose Logic Apps condition parses the alert title and assigns the tier via the Update incident action, meeting both routing requirements.

  • ✗

    Modify the Microsoft Defender for Endpoint analytics rule to include a custom mapping that assigns the incident to a specific owner based on the alert title.

    Why it's wrong here

    Analytics rules generate alerts; they cannot assign incident owners by alert title, so the tiering requirement goes unmet. Custom mappings only project entity fields into the alert schema. Analytics rules are the right tool when you need scheduled KQL detection logic producing alerts, not incident routing.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.