SC-200 Manage a security operations environment Practice Question
Your organization uses Microsoft Sentinel for security information and event management (SIEM). You need to ensure that all incidents from a specific analytics rule are automatically assigned to the 'SOC Tier 1' team. What should you configure in Microsoft Sentinel?
⚠ Common exam trap
Test-takers frequently confuse automation rules with playbooks, thinking a playbook is always required for any automated action, when in fact automation rules can directly assign ownership without invoking a Logic App.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an automation rule that triggers when the incident is created and sets the owner.
Automation rules in Microsoft Sentinel allow you to define conditions (such as incident creation) and actions (such as setting the owner) without requiring a playbook or custom code. This provides a lightweight, native way to automatically assign incidents from a specific analytics rule to the 'SOC Tier 1' team by filtering on the rule's name or ID in the automation rule's condition.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure alert enrichment in the analytics rule to add the owner.
Why it's wrong here
Alert enrichment in an analytics rule adds custom details to the alert payload, such as key-value pairs or entity mappings, to provide additional context to analysts. It does not expose any action to modify incident properties, and the incident owner is an incident-level field that is managed separately. As a result, configuring alert enrichment cannot automatically assign an owner to the resulting incidents.
- ✗
Modify the analytics rule to write the incident to a custom table accessible by the SOC team.
Why it's wrong here
Analytics rules generate alerts and incidents directly within Microsoft Sentinel; they are not designed to output incident records to custom tables in Log Analytics. Custom tables are for storing log data for querying and detection, and ingesting incident data into one would not alter the ownership field of the live incident. Therefore, writing to a custom table would only create a record outside the incident management system, leaving the incident unassigned.
- ✗
Create a playbook that assigns the incident and attach it to the analytics rule.
Why it's wrong here
Creating a playbook to assign the incident and attaching it to the analytics rule is incorrect because playbooks are primarily for complex, multi-step automated responses that execute *after* an incident has been created. While a playbook *can* assign an incident, the direct mechanism for automatically assigning *all* incidents from a specific analytics rule at the point of creation is an automation rule. Playbooks are ideal when the assignment logic is conditional, requires integration with external systems, or forms part of a larger, more intricate automated workflow.
- ✓
Create an automation rule that triggers when the incident is created and sets the owner.
Why this is correct
An automation rule can be configured to trigger when an incident is created, and its 'Set owner' action immediately assigns the incident to a designated user or group. This is the native, lightweight mechanism in Microsoft Sentinel for enforcing assignment policy at incident creation, and it can be scoped to the specific analytics rule. Because it directly updates the incident record's Owner property, it satisfies the requirement.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.