Courseiva

SC-200 Manage a security operations environment Practice Question

Your organization uses Microsoft Sentinel and you have a playbook that sends an email notification when a high-severity incident is created. You want to ensure that the playbook only runs for incidents that are not already assigned to a user. What should you configure?

⚠ Common exam trap

Test-takers frequently think a condition inside the playbook is sufficient, but Microsoft Sentinel automation rules are designed to filter incidents before triggering the playbook, making the automation rule condition the correct and more efficient choice.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure the automation rule trigger to include a condition for 'Incident owner equals null'

Automation rules in Microsoft Sentinel can include conditions that filter which incidents trigger a playbook. By configuring the automation rule with a condition for 'Incident owner equals null', the playbook will only run for incidents that are unassigned, ensuring that already assigned incidents are not processed. This approach is efficient and avoids unnecessary execution of the playbook.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Set the playbook trigger to 'When an incident is created' and add a condition inside

    Why it's wrong here

    Setting the playbook trigger to 'When an incident is created' and placing the condition inside the Logic App is inefficient because the playbook will run for every incident, regardless of whether it meets the intended criteria. Microsoft Sentinel automation rules provide a built-in condition engine that evaluates incident properties before invoking a playbook, which is the recommended place to filter incidents. Using a playbook-level condition also introduces latency and unnecessary Logic App executions, and it bypasses the centralized management that automation rules offer.

  • ✗

    Add a condition in the playbook to check if the incident is assigned

    Why it's wrong here

    Adding a condition inside the playbook to check if the incident is assigned is technically feasible using a Logic App 'Condition' action, but it suffers from the same drawback as option 1: the playbook is triggered for all incidents during the creation phase. Moreover, at the moment of incident creation the owner property is always null because Sentinel does not auto-assign incidents; the playbook would not be able to differentiate between 'unassigned' and 'assigned after creation' without additional logic. Automation rules are the recommended approach because they natively evaluate incident properties at trigger time, allowing you to run the playbook only when the owner is null.

  • ✓

    Configure the automation rule trigger to include a condition for 'Incident owner equals null'

    Why this is correct

    This is the correct approach because Microsoft Sentinel automation rules can be configured with trigger conditions based on incident properties, including the Incident owner field. By setting a condition such as 'Incident owner equals null', the automation rule will only execute when the incident is unassigned, ensuring that any associated playbook runs only for those incidents. This leverages Sentinel's native conditional logic, avoids unnecessary playbook executions, and is the recommended pattern for automating responses based on incident ownership status.

  • ✗

    Modify the analytics rule to only generate unassigned incidents

    Why it's wrong here

    Modifying the analytics rule to 'only generate unassigned incidents' is not a valid solution because analytics rules do not have any setting that controls incident assignment. In Sentinel, all newly created incidents start with an owner of null (unassigned); assignment is a separate process performed either manually or through automation rules and playbooks. Therefore, you cannot configure an analytics rule to produce a different owner value, making this option ineffective for the stated requirement.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.