Courseiva

SC-200 Respond to security incidents Practice Question

Your organization uses Microsoft Sentinel for security operations. The SOC team receives an incident that was generated from a Microsoft Defender for Cloud Apps alert. The incident involves a user who is downloading a large number of files from SharePoint Online. The analyst needs to suspend the user's account immediately to stop the potential data exfiltration. The organization has a Microsoft Sentinel playbook that can suspend a user in Microsoft Entra ID. However, the playbook is not triggering automatically. You need to ensure that the playbook runs automatically whenever a Defender for Cloud Apps alert generates an incident in Sentinel. What should you configure?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create an automation rule that triggers the playbook when an incident is created from Defender for Cloud Apps

An automation rule can be created to trigger a playbook on incident creation, specifically filtering for incidents from Defender for Cloud Apps. This enables automatic execution of the playbook to suspend the user. Option B is incorrect because a scheduled analytics rule is for generating alerts based on queries, not for triggering playbooks on existing incidents. Option C is incorrect because enabling the connector only syncs alerts, but does not automatically run playbooks; an automation rule is required. Option D is incorrect because the playbook's trigger is configured in the automation rule, not by modifying the playbook itself.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Create an automation rule that triggers the playbook when an incident is created from Defender for Cloud Apps

    Why this is correct

    Automation rules in Microsoft Sentinel evaluate incident creation and can invoke a playbook conditionally. Scoping the trigger to incidents whose alert product is Defender for Cloud Apps ensures the suspend-user playbook runs automatically on those incidents.

  • ✗

    Create a scheduled analytics rule that detects large file downloads

    Why it's wrong here

    A scheduled analytics rule queries on a time interval, so it would generate its own detections rather than fire the playbook from the existing Defender for Cloud Apps incident. Scheduled rules are the right choice when you need recurring KQL-based hunting over log data, not connector-driven automation.

  • ✗

    Enable the Microsoft Defender for Cloud Apps connector to sync alerts

    Why it's wrong here

    The connector already ingests the alerts, so enabling sync changes nothing about playbook invocation; the missing piece is an automation rule triggered on incident creation. Connector configuration is correct when alerts are absent from Sentinel entirely, not when they arrive but no playbook runs.

  • ✗

    Modify the playbook to run on alert creation

    Why it's wrong here

    Editing the playbook's internal logic changes what it does once invoked, not what invokes it; the automation rule that binds incidents to playbooks is the missing piece. Modifying playbook steps is correct when the action itself must change, for example adding a new approval or notification step.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.