Courseiva

SC-200 Manage a security operations environment Practice Question

Your organization uses Microsoft Sentinel and Microsoft Entra ID. You need to implement a solution that automatically disables a user account in Microsoft Entra ID when a high-severity incident involving that user is created in Sentinel. The solution must also send a notification to the security team. You have a playbook that disables the user and sends an email. What should you configure to trigger the playbook?

⚠ Common exam trap

SC-200 often tests the difference between automation rules and analytics rule response actions, confusing candidates about which to use for triggering playbooks on incident creation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create an automation rule that runs when an incident is created with severity High and triggers the playbook.

To automatically trigger a playbook when a high-severity incident is created in Microsoft Sentinel, you should create an automation rule. Automation rules in Microsoft Sentinel allow you to define conditions (such as incident severity) and actions (such as running a playbook). This is the native, no-code way to trigger playbooks based on incident creation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure the playbook to run on a schedule and query incidents.

    Why it's wrong here

    Incorrect: Playbooks are not scheduled; they are event-driven.

  • ✗

    Create a workbook that triggers the playbook when a high-severity incident appears.

    Why it's wrong here

    Incorrect: Workbooks cannot trigger playbooks.

  • ✓

    Create an automation rule that runs when an incident is created with severity High and triggers the playbook.

    Why this is correct

    Automation rules are Sentinel's native mechanism for triggering playbooks in response to incident creation, and they support severity-based conditions. Matching severity High ensures the playbook runs only for the relevant incidents, satisfying the automatic disablement and notification requirement.

  • ✗

    Configure the playbook as a response action in the analytics rule that generates the incident.

    Why it's wrong here

    Incorrect: Analytics rules trigger on alerts, not incidents.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

2 more ways this is tested on SC-200

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Your organization uses Microsoft Sentinel for security information and event management (SIEM). You need to ensure that all incidents from a specific analytics rule are automatically assigned to the 'SOC Tier 1' team. What should you configure in Microsoft Sentinel?

easy
  • A.Configure alert enrichment in the analytics rule to add the owner.
  • B.Modify the analytics rule to write the incident to a custom table accessible by the SOC team.
  • C.Create a playbook that assigns the incident and attach it to the analytics rule.
  • ✓ D.Create an automation rule that triggers when the incident is created and sets the owner.

Why D: Automation rules in Microsoft Sentinel allow you to define conditions (such as incident creation) and actions (such as setting the owner) without requiring a playbook or custom code. This provides a lightweight, native way to automatically assign incidents from a specific analytics rule to the 'SOC Tier 1' team by filtering on the rule's name or ID in the automation rule's condition.

Variation 2. Refer to the exhibit. You are viewing an incident in Microsoft Sentinel via the API. The incident is missing an owner. Which automation rule action would assign this incident to the SOC manager?

easy
  • A.Change incident status to: Active
  • B.Run playbook (SimplePlaybook)
  • C.Add tags: ["Malware", "Endpoint"]
  • ✓ D.Assign incident to: SOC Manager

Why D: The 'Assign incident to' action in Microsoft Sentinel automation rules directly changes the incident's owner property. By selecting 'SOC Manager' as the value, the rule sets the incident's owner field to that specific user or group, which is the exact requirement to resolve the missing owner.

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.