SC-200 Respond to security incidents Practice Question
Your organization uses Microsoft Sentinel with the Microsoft Defender XDR connector. You have a critical incident that involves multiple alerts across different services. The incident is being updated with new alerts. You need to ensure that a specific playbook runs only when the incident severity is updated to High. How should you configure the automation rule?
⚠ Common exam trap
SC-200 often tests whether candidates confuse incident-level triggers with alert-level triggers, and whether they place conditions in the automation rule versus inside the playbook, leading to unnecessary executions or missed events.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Set the trigger to 'When incident is updated' and add a condition on severity equals High.
The requirement is to run the playbook only when the incident severity is updated to High, so the automation rule must trigger on 'When incident is updated' and include a condition that severity equals High. This ensures the playbook fires on the severity change event rather than on creation or alert events.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Set the trigger to 'When an alert is created' and filter for alerts with High severity.
Why it's wrong here
The 'When an alert is created' trigger fires at the alert level, not the incident level, so it would react to each High-severity alert independently. The requirement, however, is to act when an incident is updated—for example, when a lower-severity incident is later escalated to High. An alert-creation trigger has no visibility into incident updates, so it cannot satisfy the requirement even if you filter on alert severity.
- ✓
Set the trigger to 'When incident is updated' and add a condition on severity equals High.
Why this is correct
The 'When incident is updated' trigger is the correct lifecycle hook because it fires on any change to an incident's properties, including a severity change. Adding a condition that severity equals High ensures the playbook only proceeds for incidents that are or have been set to High, satisfying the requirement. This is the recommended pattern: keep the condition in the automation rule so the playbook is only invoked when the condition is true.
- ✗
Set the trigger to 'When incident is created' and add a condition on severity equals High.
Why it's wrong here
The 'When incident is created' trigger only fires at the moment the incident is generated; it will never fire later when the incident is updated. If an incident is initially created with a severity lower than High and later escalated, the playbook would not run. Since the requirement explicitly says 'run on incident update', this trigger is insufficient.
- ✗
Configure the condition inside the playbook to check severity and exit if not High.
Why it's wrong here
Putting the severity check inside the playbook means the playbook is invoked for every incident update, even those with low or medium severity, and then it simply exits after the condition fails. This wastes compute and consumes Logic Apps execution costs, and it also delays real automation because the instance has to spin up before the filter runs. Automation rules are the correct place to filter because they evaluate conditions before the playbook is triggered, so non-matching incidents never invoke the playbook.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.