Courseiva

SC-200 Manage a security operations environment Practice Question

Your organization uses Microsoft Sentinel to manage security incidents. The security team wants to automatically close low-severity incidents after 24 hours if no activity has occurred. Which feature should you use?

⚠ Common exam trap

Candidates often confuse automation rules with playbooks, assuming automation rules can handle time delays. However, automation rules only perform immediate actions based on incident triggers; time-based scenarios require playbooks.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Playbooks

A playbook (Azure Logic App) built on a Recurrence trigger — not an incident trigger — is the correct mechanism. Automation rules only fire in response to a Sentinel incident event (created/updated) and have no built-in condition to detect elapsed inactivity time; they cannot poll on a schedule. A recurrence-triggered playbook, by contrast, can run periodically (e.g., hourly), query the Sentinel incidents REST API for Low-severity incidents that have had no updates in the last 24 hours, and close them automatically — this is Microsoft's documented pattern for automated stale-incident closure.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Playbooks

    Why this is correct

    Playbooks automate response actions triggered by alerts, but they lack a native scheduling mechanism to evaluate elapsed inactivity time and close incidents after a fixed 24-hour window. This scenario requires a time-based automation rule, which is provided by Microsoft Sentinel’s automation rules with expiry conditions. Playbooks are tempting because they can close incidents on-demand when invoked, and would be correct for orchestrating complex, multi-step responses to a specific alert type.

  • ✗

    Automation rules

    Why it's wrong here

    Automation rules in Microsoft Sentinel can trigger on incident creation or status updates, and include a condition to check the incident’s severity level (low) and a time-based trigger that fires after 24 hours of inactivity. This satisfies the stem’s requirement to close low-severity incidents automatically when no activity has occurred within that window, without requiring a separate playbook or logic app.

  • ✗

    Watchlists

    Why it's wrong here

    Watchlists are static reference tables that administrators upload to Microsoft Sentinel to store tabular data, such as high-risk IPs or asset tags, and then use for correlation, enrichment, and join operations in analytics rule queries. They are purely passive data structures with no execution context, scheduling capability, or action-oriented workflow, so they cannot evaluate incident inactivity over time or close an incident. Because they lack any automation logic, selecting Watchlists for closing low-severity incidents after 24 hours would be functionally impossible.

  • ✗

    Analytics rules

    Why it's wrong here

    Analytics rules are Sentinel detections that define a periodic query or alert condition, and when matched, they generate an incident—meaning they are responsible for the creation and, in some cases, the suppression of alerts, not for the closure of existing incidents. An analytics rule runs on a fixed schedule (for example, every 5 minutes) and evaluates raw event data, not the state or last-modified timestamp of an incident, so it has no mechanism to detect a 24-hour no-activity period or to invoke a closure action. While analytics rules can associate alerts with incidents, they cannot act on an incident after it has already been generated, making them an incorrect choice for this time-based closure automation.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.