Courseiva

SC-200 Respond to security incidents Practice Question

Your organization uses Microsoft Sentinel with the Microsoft Defender XDR connector. You have a critical incident that involves multiple alerts across different services. The incident is being updated with new alerts. You need to ensure that a specific playbook runs only when the incident severity is updated to High. How should you configure the automation rule?

⚠ Common exam trap

SC-200 often tests whether candidates confuse incident-level triggers with alert-level triggers, and whether they place conditions in the automation rule versus inside the playbook, leading to unnecessary executions or missed events.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Set the trigger to 'When incident is updated' and add a condition on severity equals High.

The requirement is to run the playbook only when the incident severity is updated to High, so the automation rule must trigger on 'When incident is updated' and include a condition that severity equals High. This ensures the playbook fires on the severity change event rather than on creation or alert events.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Set the trigger to 'When an alert is created' and filter for alerts with High severity.

    Why it's wrong here

    The 'When an alert is created' trigger fires at the alert level, not the incident level, so it would react to each High-severity alert independently. The requirement, however, is to act when an incident is updated—for example, when a lower-severity incident is later escalated to High. An alert-creation trigger has no visibility into incident updates, so it cannot satisfy the requirement even if you filter on alert severity.

  • ✓

    Set the trigger to 'When incident is updated' and add a condition on severity equals High.

    Why this is correct

    The 'When incident is updated' trigger is the correct lifecycle hook because it fires on any change to an incident's properties, including a severity change. Adding a condition that severity equals High ensures the playbook only proceeds for incidents that are or have been set to High, satisfying the requirement. This is the recommended pattern: keep the condition in the automation rule so the playbook is only invoked when the condition is true.

  • ✗

    Set the trigger to 'When incident is created' and add a condition on severity equals High.

    Why it's wrong here

    The 'When incident is created' trigger only fires at the moment the incident is generated; it will never fire later when the incident is updated. If an incident is initially created with a severity lower than High and later escalated, the playbook would not run. Since the requirement explicitly says 'run on incident update', this trigger is insufficient.

  • ✗

    Configure the condition inside the playbook to check severity and exit if not High.

    Why it's wrong here

    Putting the severity check inside the playbook means the playbook is invoked for every incident update, even those with low or medium severity, and then it simply exits after the condition fails. This wastes compute and consumes Logic Apps execution costs, and it also delays real automation because the instance has to spin up before the filter runs. Automation rules are the correct place to filter because they evaluate conditions before the playbook is triggered, so non-matching incidents never invoke the playbook.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.