SC-200 Manage a security operations environment Practice Question
Your organization uses Microsoft Sentinel and you need to ensure that incidents are automatically closed when a related playbook completes successfully. What should you configure?
⚠ Common exam trap
Candidates often think adding a 'Close incident' action inside the playbook is sufficient, but they overlook that this action closes the incident immediately when executed, not after the entire playbook completes, which can lead to premature closure if the playbook has subsequent steps that fail.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an automation rule that triggers after the playbook runs and closes the incident
Automation rules in Microsoft Sentinel can be configured to trigger after a playbook completes, and one of the available actions is to close an incident. This ensures that the incident is automatically closed only when the playbook has successfully finished, providing a reliable and automated closure mechanism without manual intervention.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create an automation rule that triggers after the playbook runs and closes the incident
Why this is correct
An automation rule is a native Sentinel capability that can be configured with the 'When incident is updated' trigger and a condition that matches the playbook's execution context, such as a tag the playbook added. After that condition is met, the rule's 'Change status' action can set the incident to 'Closed', giving you a declarative, no-code closure path that runs immediately after the playbook finishes. This keeps the closure logic outside the Logic App, so you can modify or reuse it without redeploying the playbook.
- ✗
Add a 'Close incident' action in the playbook
Why it's wrong here
While a playbook (a Logic App) can technically close an incident by invoking the 'Update incident' action in the Sentinel connector, embedding this action inside the playbook hard-codes the closure behavior into the Logic App. That makes the rule harder to audit and update, forces the playbook to branch internally for every closure scenario, and bypasses the centralized management that automation rules provide. Even though a playbook can close an incident, the requirement is best met with an automation rule that runs after the playbook, so this option is not the best answer.
- ✗
Configure the analytics rule to close incidents automatically
Why it's wrong here
Analytics rules, such as scheduled query rules or Microsoft security analytics rules, are designed only to detect threats and generate alerts or incidents based on query results and event-grouping settings. Their configuration surface includes incident creation properties like severity, tactics, and alert grouping, but it does not include any option to automatically close incidents. Closing an incident is an incident lifecycle operation that occurs after the incident is created, so it is outside the scope of the analytics rule configuration in Microsoft Sentinel.
- ✗
Use a workbook to manually close incidents
Why it's wrong here
Workbooks in Microsoft Sentinel are interactive dashboards built on Azure Workbooks that display metrics, queries, and visualizations; they do not contain automated actions that can change incident state. Although a workbook can include a link that takes an analyst to an incident, closing the incident still requires a manual click in the portal—there is no native workbook action to set the status to 'Closed'. Because the goal is automatic closure after a playbook runs, a workbook provides no automation and is therefore incorrect.
Go deeper
Related to this question
About these practice questions
This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.