Courseiva

SC-200 Workbook Practice Question

Your organization uses Microsoft Sentinel. The SOC manager wants to track the average time to triage incidents. You need to create a report that shows this metric. What should you use?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a workbook that uses KQL to query incident data and display the average time.

Microsoft Sentinel workbooks can be built using Kusto Query Language (KQL) to query the SecurityIncident table and compute the average time to triage, allowing the SOC manager to track this metric. Option B is incorrect because playbooks are designed for automation and response, not for creating reports. Option C is incorrect because automation rules are for automated incident handling, not for reporting or logging custom metrics. Option D is incorrect because analytics rules are used to generate alerts based on queries, not to produce reports.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Create a workbook that uses KQL to query incident data and display the average time.

    Why this is correct

    Workbooks query the Sentinel data lake with KQL, so incident records can be aggregated to compute average triage duration and rendered as a report. Analytics rules generate incidents and automation rules respond to them; neither produces the requested metric visualisation.

  • ✗

    Create a playbook that sends a report via email.

    Why it's wrong here

    A playbook automates response actions and can email output, but it does not compute or persist the average triage duration metric. Playbooks are tempting because they run on incidents and can deliver reports, and would be correct when the requirement is to automate an investigation or notification workflow.

  • ✗

    Create an automation rule that logs the triage time to a custom table.

    Why it's wrong here

    Automation rules trigger playbooks on incident creation or update; logging a timestamp to a custom table does not calculate the average triage time the manager wants. They are tempting because they respond to incident lifecycle events, and would be correct when the requirement is to orchestrate actions such as assigning or tagging incidents.

  • ✗

    Create an analytics rule that calculates the time to triage.

    Why it's wrong here

    Analytics rules generate alerts by matching events against detection logic; they do not aggregate incident triage durations into a reportable metric. They are tempting because they run scheduled KQL queries, and would be correct when the requirement is to detect suspicious activity and create incidents.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.