Courseiva

SC-200 Respond to security incidents Practice Question

Your organization uses Microsoft Sentinel and has enabled UEBA (User and Entity Behavior Analytics). You notice a series of incidents involving anomalous logon times for a privileged user. You want to automate the response to disable the user's account in Microsoft Entra ID when such incidents are created. What should you configure?

⚠ Common exam trap

It's easy for candidates to assume UEBA or analytics rules can directly perform remediation actions, but in Sentinel, detection and response are separated—analytics rules only detect, while playbooks (via automation rules) execute the response.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create an automation rule that runs a playbook when an incident from the UEBA analytics rule is created, and configure the playbook to disable the user in Microsoft Entra ID.

Microsoft Sentinel automation rules can trigger a playbook when an incident is created by a specific analytics rule (e.g., a UEBA-based rule). The playbook, built in Azure Logic Apps, can then use the Microsoft Graph API to disable the user's account in Microsoft Entra ID. This provides a fully automated, event-driven response to anomalous logon time incidents without manual intervention.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Create an automation rule that runs a playbook when an incident from the UEBA analytics rule is created, and configure the playbook to disable the user in Microsoft Entra ID.

    Why this is correct

    In Microsoft Sentinel, an automation rule is the correct mechanism to trigger a playbook when an incident is created. Since the UEBA analytics rule generates incidents for suspicious behavior, you attach an automation rule to that rule that invokes a playbook. The playbook can then call Microsoft Entra ID to disable a user account, providing immediate, coordinated incident response.

  • ✗

    Create an analytics rule that triggers on UEBA anomalies and directly disables the user.

    Why it's wrong here

    Analytics rules in Microsoft Sentinel are designed to detect threats and create alerts or incidents based on query results. They do not have built-in actions to directly modify external resources such as disabling a user in Microsoft Entra ID. To perform a remediation action, you must use a playbook, which is executed by an automation rule, not by the analytics rule itself.

  • ✗

    Add the user to a watchlist and create a playbook that runs on a schedule.

    Why it's wrong here

    Watchlists are reference data structures used to enrich or correlate detections; they are not triggers for automated response. A playbook that runs on a schedule is not event-driven; it executes at fixed intervals, which could introduce significant delay and miss the immediate response expected for an active UEBA incident. This approach bypasses Sentinel's incident lifecycle and is not a supported automation pattern for real-time response.

  • ✗

    Configure UEBA to automatically disable the user when anomalous behavior is detected.

    Why it's wrong here

    UEBA (User and Entity Behavior Analytics) in Microsoft Sentinel is an analytics engine that models user behavior and identifies anomalies. It does not include any native response actions or the ability to disable accounts; it simply generates alerts and incidents based on calculated risk scores. Any remediation, such as disabling a user, must be performed by an external automation tool like a playbook triggered by an automation rule.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.