Courseiva

SC-200 Respond to security incidents Practice Question

Your organization uses Microsoft Sentinel and has enabled the Microsoft 365 Defender connector. You want to automatically assign incidents to a specific analyst team based on the incident severity and type. Which component should you configure?

⚠ Common exam trap

The SC-200 exam often tests the distinction between automation rules (for incident management) and playbooks (for response actions), leading candidates to choose playbooks when a simpler, built-in rule suffices.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Automation rule in Microsoft Sentinel

Automation rules in Microsoft Sentinel allow you to automatically assign incidents to specific teams based on conditions like severity and type. This is the correct component because it provides a no-code, rule-based engine for incident management tasks, including assignment, without requiring custom logic or external automation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Analytics rule in Microsoft Sentinel

    Why it's wrong here

    Analytics rules in Microsoft Sentinel are query-based detection mechanisms that generate alerts when specific data patterns, such as suspicious sign-in activity, are matched. They define the alert conditions themselves—for example, the KQL query, frequency, and alert threshold—but they are not responsible for incident management actions like assigning an owner. Because the requirement is to set an owner for an incident, an analytics rule alone cannot achieve that outcome.

  • ✗

    Workbook in Microsoft Sentinel

    Why it's wrong here

    Workbooks in Microsoft Sentinel provide interactive reporting and visualization of collected security data, using Azure Workbooks under the hood to display metrics, trends, and KQL query results. They are designed for analysis and intelligence gathering, not for executing automated remediation or operational workflows. Setting an incident owner is an action performed on the incident entity, so a reporting surface cannot perform that kind of state-changing operation.

  • ✓

    Automation rule in Microsoft Sentinel

    Why this is correct

    Automation rules in Microsoft Sentinel are the native, lightweight mechanism for automating incident management tasks, including assigning an owner, changing status, or applying tags, without requiring a Logic Apps connector or additional code. You can create a rule with a condition like 'When incident is created' and an action 'Assign owner' to set the incident owner to a specific user or group. This is simpler, more performant, and directly integrated into the incident pipeline compared to custom code or playbooks.

  • ✗

    Custom playbook in Microsoft Sentinel

    Why it's wrong here

    A custom playbook in Microsoft Sentinel is an Azure Logic Apps-based workflow that can perform a wide range of actions, including assigning an incident owner via the Microsoft Sentinel API or a connector. However, using a playbook for a simple owner assignment is overkill because it introduces deployment, size limits, execution cost, and maintenance overhead that automation rules avoid. For just assigning an owner, the built-in automation rule action is the recommended, more efficient choice.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.