Courseiva

SC-200 Respond to security incidents Practice Question

Your organization uses Microsoft Sentinel. A security analyst reports that an incident was automatically closed without investigation. You need to identify why the incident was closed automatically. Which Sentinel feature should you review?

⚠ Common exam trap

A common mix-up: candidates confuse automation rules with playbooks, thinking playbooks directly close incidents, but in Sentinel, playbooks are only triggered by automation rules and the closure action is defined in the automation rule itself, not in the playbook.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Automation rules

Automation rules in Microsoft Sentinel allow you to define automated responses to incidents, including automatically closing them based on specific conditions (e.g., severity, title, or entity). If an incident was closed without investigation, an automation rule likely triggered a closure action, such as setting the status to 'Closed' with a specific classification. Reviewing the automation rules list and their trigger conditions will reveal which rule caused the automatic closure.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Analytics rules

    Why it's wrong here

    Analytics rules are scheduled or near-real-time query rules that apply threat detection logic to ingested data and generate incidents when matches occur. They are inherently creation-only artifacts: their output is a new incident, and they contain no action blocks to set its status, severity, or closure reason. Even when they automatically run playbooks via automation rules, that invokes a separate layer, while the analytics rule itself never modifies or closes an existing incident.

  • ✓

    Automation rules

    Why this is correct

    Automation rules are Sentinel's native, rule-based engine for incident lifecycle automation, evaluated when an incident is created or updated. They support one or more conditions (e.g., severity, title, entity) and multiple actions, including setting the incident status to 'Resolved/Closed' and specifying a closure classification and comment. Because they are first-class components that directly execute incident-state changes without external dependencies, they are the definitive mechanism for automatically closing incidents.

  • ✗

    Playbooks

    Why it's wrong here

    Playbooks are Azure Logic Apps workflows that perform complex, multi-step operations on Sentinel data, and they do contain a 'Update Incident' or 'Close Incident' action when the Sentinel connector is used. However, they are reactive and never auto-trigger on their own; an automation rule must invoke them as an action, or an analyst must manually run them. Thus, while a playbook can execute the closure, the automation rule is what sets that desired outcome in motion, making the playbook the executor rather than the cause.

  • ✗

    Workbooks

    Why it's wrong here

    Workbooks are interactive reporting canvases that visualize Sentinel data with queries, charts, and tiles, providing operational dashboards for analysts. They operate strictly on the read side of the API and expose no configuration, logic, or action to alter incident data, so they cannot close, update, or create incidents. Their only relationship to closure is displaying the current status of incidents in a report.

  • ✗

    Watchlists

    Why it's wrong here

    Watchlists are editable CSV-based collections of structured reference data stored in Sentinel, used to enrich or correlate events in analytics rule queries and hunting, for example, a list of critical systems or VIP users. They are passive lookup tables with no attachment to the incident management pipeline, and they do not contain any code or actions that could change an incident's status, severity, or owner. Consequently, they cannot initiate or perform the closure of an incident.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.