Courseiva

SC-200 Manage a security operations environment Practice Question

Your organization uses Microsoft Sentinel and Microsoft Defender XDR. A security analyst reports that incidents related to ransomware are not being automatically triaged by the SOC automation playbook. You confirm that the playbook is enabled and connected to the analytics rule. What is the most likely cause of the issue?

⚠ Common exam trap

Candidates often assume the playbook or analytics rule association is the problem, when in fact the automation rule's provider condition silently filters out the incident, causing the playbook to never trigger despite all other connections being correct.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The automation rule that triggers the playbook is set to run only when the incident is created by a specific provider (e.g., Microsoft Defender XDR), but the incident is created by Microsoft Sentinel.

The automation rule that triggers the playbook is configured with a condition that restricts it to incidents created by a specific provider, such as Microsoft Defender XDR. However, the ransomware incident is being created by Microsoft Sentinel (e.g., via an analytics rule), not by Microsoft Defender XDR. This provider mismatch prevents the automation rule from firing, so the playbook never runs, even though the playbook itself is enabled and connected to the analytics rule.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The Microsoft Sentinel workspace is in a different region than Microsoft Defender XDR.

    Why it's wrong here

    The Microsoft Sentinel workspace's region does not affect the ability of an automation rule to trigger a playbook; automation rules execute entirely within the Sentinel workspace and do not depend on Defender XDR's geographic location. A region mismatch only has implications for data residency, replication latency, or where logs are stored, not for the event-driven trigger mechanism. Consequently, even with the workspace in a different region from Defender XDR, the automation rule would still fire on incident creation.

  • ✗

    The incident is not being created by the analytics rule.

    Why it's wrong here

    The analyst confirmed that the incident is indeed being created by the analytics rule, so any suggestion that the rule is not producing it is factually incorrect. Moreover, automation rules apply to all incidents created in the workspace unless explicitly filtered by conditions such as analytics rule name or incident properties. Even if the incident were created by a different rule, the automation rule would still trigger unless a specific filter excluded it.

  • ✗

    The playbook is not associated with the correct analytics rule in the automation rule.

    Why it's wrong here

    The playbook being incorrectly associated with the analytics rule is not the root cause because the user has already verified the playbook is connected to the appropriate automation rule. Automation rules can be configured with conditions that filter on the analytics rule that created the incident, so if those conditions are misconfigured it would be a provider mismatch, not an association error. Since the incident is generated and the playbook is linked, the problem lies in the automation rule's condition logic rather than a missing or incorrect playbook association.

  • ✓

    The automation rule that triggers the playbook is set to run only when the incident is created by a specific provider (e.g., Microsoft Defender XDR), but the incident is created by Microsoft Sentinel.

    Why this is correct

    If the automation rule includes a condition using the 'Provider' property — such as requiring it to equal 'Microsoft Defender XDR' — then an incident created by a Microsoft Sentinel analytics rule will not match. Analytics rule incidents have their Provider field set to 'Microsoft Sentinel' by default, regardless of the source data source, so the rule's condition evaluates to false and the playbook never triggers. To fix this, remove the provider filter or change it to 'Microsoft Sentinel' (or set it to 'Other' depending on the version), ensuring the automation rule runs for incidents generated by the desired analytics rule.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.