SC-200 Manage a security operations environment Practice Question
Your organization uses Microsoft Sentinel to manage security incidents. The security team wants to automatically assign incidents to the appropriate analyst based on the incident’s severity and category. Which feature should you configure?
⚠ Common exam trap
Many exam-takers confuse playbooks (which can also assign incidents via Logic Apps) with automation rules, but automation rules are the simpler, native feature for direct assignment without needing to build a custom workflow.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Automation rules
Automation rules in Microsoft Sentinel allow you to automatically assign incidents to specific analysts or teams based on conditions such as severity and category. This is the correct feature because it provides a rule-based engine that triggers on incident creation or update, enabling automatic assignment without manual intervention.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Automation rules
Why this is correct
Automation rules are the native Sentinel capability that can automatically assign incidents to an owner or team based on incident conditions like severity, product name, or entity. When an incident is created or updated, the rule evaluates its criteria and directly sets the 'Owner' field, enabling immediate triage and workload routing without requiring external logic. This is the correct answer because assignment is a first-class automation action, not a side effect of detection or a separate workflow.
- ✗
Analytics rules
Why it's wrong here
Analytics rules use KQL queries to detect threats and generate incidents from matched results, but their scope ends at detection and alert creation. They have no actions to set the incident owner or otherwise modify the incident's assignment state, so they cannot fulfill the requirement to automatically assign incidents. Assignment must be performed downstream by automation rules or manually by an analyst.
- ✗
Playbooks
Why it's wrong here
Playbooks, built on Azure Logic Apps, execute automated response workflows such as posting to Microsoft Teams, running adaptive cards, or sending emails, and can even change an incident owner by invoking a Microsoft Sentinel connector action. However, they are not the primary or simplest native mechanism for assignment; they require a separate trigger (usually from an automation rule) and involve custom logic, so they are not the direct, built-in way to assign incidents. The correct native assignment functionality is provided by automation rules directly.
- ✗
Watchlists
Why it's wrong here
Watchlists are collections of tabular data—such as known malicious IPs, high-value asset names, or employee lists—that you upload and use within analytics rules to enrich, filter, or correlate detection logic. They do not perform any workflow actions like incident assignment; they exist solely as reference data for queries. Consequently, watchlists cannot assign incidents, as they lack any execution or manipulation capability over incident records.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.