SC-200 Respond to security incidents Practice Question
Your organization uses Microsoft Sentinel. An incident is created from a fusion detection that combines multiple signals. You need to ensure that when the incident is resolved, all related alerts are also resolved automatically. What should you do?
⚠ Common exam trap
It's easy for candidates to confuse automation rule triggers (incident creation vs. closure) or assume that closing an incident automatically closes its alerts, which is not the default behavior in Microsoft Sentinel.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an automation rule triggered when an incident is closed, with the action 'Close alert'
An automation rule triggered when an incident is closed can include the action 'Close alert', which automatically closes all alerts linked to that incident. This ensures that when the incident is resolved, all related alerts are also resolved without manual intervention.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create an automation rule triggered when an incident is closed, with the action 'Close alert'
Why this is correct
In Microsoft Sentinel, an automation rule can be triggered when an incident's status changes to Closed, and its 'Close alert' action explicitly resolves all linked alerts. This ensures that the security operations team does not have to manually close each alert and that the alert-state lifecycle matches the incident-state lifecycle. Conditions such as severity, owner, or tactic can also be applied, making this the correct, supported mechanism to accomplish the goal.
- ✗
Create a playbook triggered on incident creation that closes alerts
Why it's wrong here
A playbook triggered on incident creation executes immediately after a new incident is generated, typically while the incident is still in a 'New' or 'Active' state. Closing alerts at that point would occur before investigation or resolution, and the playbook would not re-run when the incident is later closed. Therefore, it does not fulfill the requirement of closing alerts upon incident closure; the playbook would instead need to be invoked from an automation rule that triggers on incident status change, such as when the status is set to Closed.
- ✗
Create an automation rule triggered when an alert is created
Why it's wrong here
An automation rule triggered when an alert is created fires at the moment each alert is generated, which is prior to or concurrent with incident creation. Using its 'Close alert' action there would close alerts immediately, prematurely preventing further correlation, investigation, and response. It would not be tied to the incident's eventual resolution—an incident may remain open for days—so this trigger is functionally out of sync with the desired behavior of resolving alerts only after the incident is closed.
- ✗
Configure the analytics rule to close alerts when the incident is resolved
Why it's wrong here
Analytics rules in Microsoft Sentinel, including scheduled and near-real-time rules, are responsible for defining which alerts are generated and optionally creating incidents from them; they do not include any setting to close alerts when an incident is resolved. Alert status management is handled by automation rules, playbooks, or manual triage, not by the analytics rule's configuration. Therefore, looking for such a setting within the analytics rule is an invalid approach to this requirement.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.