Courseiva

SC-200 Respond to security incidents Practice Question

Your organization uses Microsoft Sentinel. You have a requirement to automatically add a tag to incidents that involve a specific user. The tag should be added when the incident is created. What should you configure?

⚠ Common exam trap

Many exam-takers confuse the ability to configure tags directly in an analytics rule (which is not supported) with the correct method of using automation rules and playbooks to add tags after incident creation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create an automation rule that triggers on incident creation and runs a playbook with the 'Add tag' action.

Automation rules in Microsoft Sentinel can be configured to trigger when an incident is created, and they can run a playbook that includes the 'Add tag' action. This allows you to automatically tag incidents involving a specific user by incorporating logic within the playbook to check for that user's presence in the incident entities.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Add the user to a watchlist and create a fusion rule.

    Why it's wrong here

    Adding a user to a watchlist only creates a reusable reference dataset for detection and investigation; it does not perform any automatic incident tagging. A fusion rule, while able to correlate alerts and create incidents, operates on alert telemetry and cannot append custom properties like tags to incidents it generates. Neither component exposes an action to modify incident metadata, so this combination fails to meet the requirement of automatically tagging incidents.

  • ✓

    Create an automation rule that triggers on incident creation and runs a playbook with the 'Add tag' action.

    Why this is correct

    Automation rules in Microsoft Sentinel are the native orchestration mechanism that can trigger on incident creation (or status change) and execute a playbook. A playbook built in Azure Logic Apps can include the 'Add tag' action from the Sentinel connector, which appends the desired tag to the incident. This directly satisfies the requirement by applying the tag automatically, and it is the documented method for enriching incidents with custom labels because analytics rules and watchlists lack this capability.

  • ✗

    Modify the analytics rule to include a tag in the incident configuration.

    Why it's wrong here

    Analytics rules in Sentinel define detection logic (e.g., KQL queries, alert grouping, and incident settings) but their configuration window does not include any field to specify incident tags. The incident creation process consumes the rule's alert details but only carries over properties like severity, status, and owner; tags are not part of the schema exposed by the analytics rule. Therefore, modifying the rule cannot produce automatically tagged incidents, making this option technically infeasible.

  • ✗

    Enable entity behavior analytics to automatically tag incidents.

    Why it's wrong here

    Entity behavior analytics (EBA) uses machine learning to identify anomalous user, host, and entity activities, generating alerts that can be turned into incidents. However, EBA's output is limited to alerts and incidents with predefined severity and tactics; it has no configuration for assigning tags to those incidents. Tag assignment is a post-incident enrichment action that EBA does not perform, so enabling it will not automatically tag any incident, including those created from EBA alerts.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.