SC-200 Respond to security incidents Practice Question
Your organization uses Microsoft Sentinel and has several analytics rules that generate incidents from various data sources. The SOC team is overwhelmed by the number of incidents. You need to implement a triage system that automatically assigns incidents to different analysts based on the incident's tactics and severity. You also want to send a notification to the assigned analyst via Teams. What should you do?
⚠ Common exam trap
The trap is choosing a single catch-all playbook or a manual dashboard instead of using automation rules with tactic/severity conditions — the exam tests whether you know automation rules are the conditional trigger layer and playbooks are the action layer.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create multiple automation rules that trigger on incident creation, each with conditions for specific tactics and severity, and then run a playbook that assigns the incident to an analyst and sends a Teams notification.
Automation rules in Microsoft Sentinel trigger on incident creation and support conditions based on incident properties such as tactics and severity, and they can invoke a playbook. Creating multiple automation rules with tactic/severity conditions that each run an assignment-and-notification playbook delivers the required automatic triage and Teams alerting. This is the native, supported pattern for conditional incident routing.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create multiple automation rules that trigger on incident creation, each with conditions for specific tactics and severity, and then run a playbook that assigns the incident to an analyst and sends a Teams notification.
Why this is correct
Automation rules trigger on incident creation and can filter by tactics and severity, then invoke a playbook. The playbook performs the assignment and posts the Teams notification, satisfying both the triage routing and alerting requirements without manual intervention.
- ✗
Use a workbook to create a triage dashboard and instruct analysts to manually claim incidents from the dashboard.
Why it's wrong here
A workbook only displays data; it cannot assign incidents or trigger Teams notifications, so triage stays manual. It tempts because workbooks visualise incident trends, which suits reporting and hunting dashboards, but automation requires an automation rule or playbook acting on incident creation.
- ✗
Modify each analytics rule to include a custom details field that specifies the analyst, and use a playbook to send Teams notification based on that field.
Why it's wrong here
Custom details are static fields populated from analytics query output, so they cannot dynamically map tactics and severity to the correct analyst. They tempt as a way to enrich incidents, which is their real purpose, but assignment and Teams notification need an automation rule.
- ✗
Create a single playbook that checks the incident's tactics and severity, assigns it to the appropriate analyst, and sends a Teams notification, then configure that playbook to run automatically on all new incidents.
Why it's wrong here
A single playbook triggered on all incidents cannot branch assignment by tactics and severity without duplicating logic, and Sentinel's automation rule is the native trigger for per-incident assignment. Playbooks suit orchestrating response actions once an incident already exists and is assigned.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.