SC-200 Manage a security operations environment Practice Question
Your organization uses Microsoft Sentinel to manage security incidents. You need to ensure that critical incidents are automatically assigned to the senior security analyst on duty. What should you configure?
⚠ Common exam trap
The trap is choosing a playbook because it sounds more powerful, but automation rules are the native, simpler feature for incident assignment—playbooks are overkill and require more setup.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure an automation rule with an 'Assign incident' action
Automation rules in Microsoft Sentinel allow you to automatically assign incidents to a specific owner based on conditions such as severity or title. Configuring an automation rule with the 'Assign incident' action ensures critical incidents are routed to the senior analyst on duty without manual intervention. This is the native, no-code method for incident assignment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Configure an automation rule with an 'Assign incident' action
Why this is correct
An automation rule with the 'Assign incident' action runs on incident creation, setting the owner to the senior analyst on duty. This directly satisfies the automatic assignment requirement, as analytics rules detect incidents but cannot assign ownership themselves.
- ✗
Modify the analytics rule to set the owner in the incident creation
Why it's wrong here
Analytics rule incident creation cannot dynamically resolve which analyst is on duty; the owner field is static, so it cannot target the current senior analyst. It is tempting because analytics rules do create incidents and can preset an owner, which suits fixed team assignment rather than a rotating on-call rota.
- ✗
Create a playbook that assigns incidents
Why it's wrong here
A playbook triggers only after incident creation, so assignment is not guaranteed at creation and depends on the automation rule firing correctly. Playbooks suit enrichment, notification and remediation tasks; they are the right choice when post-creation orchestration is required rather than initial ownership.
- ✗
Use a workbook to filter incidents by severity and assign manually
Why it's wrong here
A workbook is a read-only visualisation surface; it cannot assign incidents, so the analyst must act manually and critical incidents may sit unowned. Automation rules assign incidents by severity, entity or analytics rule. Workbooks suit reporting and investigation dashboards, not automated ownership.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.