SC-200 Manage a security operations environment Practice Question
Your organization uses Microsoft Sentinel and you have a playbook that sends an email notification when a high-severity incident is created. You want to ensure that the playbook only runs for incidents that are not already assigned to a user. What should you configure?
⚠ Common exam trap
Test-takers frequently think a condition inside the playbook is sufficient, but Microsoft Sentinel automation rules are designed to filter incidents before triggering the playbook, making the automation rule condition the correct and more efficient choice.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure the automation rule trigger to include a condition for 'Incident owner equals null'
Automation rules in Microsoft Sentinel can include conditions that filter which incidents trigger a playbook. By configuring the automation rule with a condition for 'Incident owner equals null', the playbook will only run for incidents that are unassigned, ensuring that already assigned incidents are not processed. This approach is efficient and avoids unnecessary execution of the playbook.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Set the playbook trigger to 'When an incident is created' and add a condition inside
Why it's wrong here
Setting the playbook trigger to 'When an incident is created' and placing the condition inside the Logic App is inefficient because the playbook will run for every incident, regardless of whether it meets the intended criteria. Microsoft Sentinel automation rules provide a built-in condition engine that evaluates incident properties before invoking a playbook, which is the recommended place to filter incidents. Using a playbook-level condition also introduces latency and unnecessary Logic App executions, and it bypasses the centralized management that automation rules offer.
- ✗
Add a condition in the playbook to check if the incident is assigned
Why it's wrong here
Adding a condition inside the playbook to check if the incident is assigned is technically feasible using a Logic App 'Condition' action, but it suffers from the same drawback as option 1: the playbook is triggered for all incidents during the creation phase. Moreover, at the moment of incident creation the owner property is always null because Sentinel does not auto-assign incidents; the playbook would not be able to differentiate between 'unassigned' and 'assigned after creation' without additional logic. Automation rules are the recommended approach because they natively evaluate incident properties at trigger time, allowing you to run the playbook only when the owner is null.
- ✓
Configure the automation rule trigger to include a condition for 'Incident owner equals null'
Why this is correct
This is the correct approach because Microsoft Sentinel automation rules can be configured with trigger conditions based on incident properties, including the Incident owner field. By setting a condition such as 'Incident owner equals null', the automation rule will only execute when the incident is unassigned, ensuring that any associated playbook runs only for those incidents. This leverages Sentinel's native conditional logic, avoids unnecessary playbook executions, and is the recommended pattern for automating responses based on incident ownership status.
- ✗
Modify the analytics rule to only generate unassigned incidents
Why it's wrong here
Modifying the analytics rule to 'only generate unassigned incidents' is not a valid solution because analytics rules do not have any setting that controls incident assignment. In Sentinel, all newly created incidents start with an owner of null (unassigned); assignment is a separate process performed either manually or through automation rules and playbooks. Therefore, you cannot configure an analytics rule to produce a different owner value, making this option ineffective for the stated requirement.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.