Courseiva

SC-200 Manage a security operations environment Practice Question

Your organization uses Microsoft Sentinel for security operations. You need to ensure that critical alerts are automatically assigned to the appropriate SOC tier for investigation. What should you configure in Microsoft Sentinel?

⚠ Common exam trap

Many exam-takers confuse the capabilities of analytics rules (which generate incidents) with automation rules (which handle post-creation actions like owner assignment), leading them to incorrectly select Option C.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create an automation rule that sets the incident owner

Automation rules in Microsoft Sentinel allow you to automatically assign incidents to specific owners based on conditions like severity or alert type. This ensures critical alerts are routed to the appropriate SOC tier without manual intervention, directly meeting the requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a playbook that assigns the incident to a user

    Why it's wrong here

    A playbook runs only after an incident is created, so it cannot assign incidents at creation time based on alert severity; automation rules handle that. Playbooks suit enrichment, notification or remediation workflows triggered post-incident, not the initial tier routing the scenario requires.

  • ✗

    Use a watchlist to map alert types to owners

    Why it's wrong here

    A watchlist stores reference data for enrichment or lookup, not incident routing logic; it cannot assign owners automatically. Watchlists suit scenarios such as mapping IP addresses to asset owners for enrichment queries, not the automated tier assignment this scenario demands.

  • ✗

    Configure an analytics rule to set the owner

    Why it's wrong here

    Analytics rules generate incidents but cannot set the owner; Sentinel assigns ownership through automation rules, not rule configuration. Setting an owner on an analytics rule is tempting because the rule defines the incident, yet ownership assignment requires a separate automation rule triggered on incident creation.

  • ✓

    Create an automation rule that sets the incident owner

    Why this is correct

    Automation rules in Microsoft Sentinel trigger on incident creation and can set the owner field, routing critical alerts to the correct SOC tier. This satisfies the requirement for automatic assignment without manual triage, since analytics rules alone cannot assign owners.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.