SC-200 Respond to security incidents Practice Question
Your organization uses Microsoft Sentinel. You have an incident that involves multiple alerts. You want to automatically assign the incident to the appropriate analyst based on the alert type. What should you use?
⚠ Common exam trap
SC-200 often tests the confusion between automation rules and playbooks, tricking candidates into selecting playbooks for simple assignment tasks that automation rules handle natively.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an automation rule with an 'Assign incident to owner' action.
An automation rule with an 'Assign incident to owner' action is the correct mechanism to automatically assign incidents based on alert type. Automation rules in Microsoft Sentinel support conditions on incident properties (including alert type/analytics rule) and can assign the incident to a specific owner or group. This directly fulfills the requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a playbook that assigns the incident.
Why it's wrong here
Creating a playbook fails here because playbooks are designed to automate actions *after* an incident is created or updated, not to define the initial conditional assignment rules based on alert type. While a playbook can assign an incident, it lacks the structured mechanism for defining rule-based, conditional assignment logic based on incident properties like alert type. Playbooks are tempting as they automate many Sentinel tasks, such as enriching incidents, notifying teams, or performing remediation actions, where they would be the correct choice.
- ✗
Configure the analytics rule to set the incident owner.
Why it's wrong here
Analytics rule incident-owner settings apply a static owner to every incident the rule generates, so they cannot route by alert type across a multi-alert incident. It is tempting because it automates assignment, and suits single-source rules with one known owner, but dynamic per-type routing requires automation rules.
- ✗
Use a workbook to filter incidents by alert type.
Why it's wrong here
Workbooks render dashboards and filter views for analysts; they cannot assign incident ownership. It is tempting because filtering by alert type surfaces the relevant incidents, and suits triage reporting, but assignment demands an automation rule or playbook that writes the owner field.
- ✓
Create an automation rule with an 'Assign incident to owner' action.
Why this is correct
Automation rules in Microsoft Sentinel trigger on incident creation and can run the 'Assign incident to owner' action, routing incidents by alert type or other conditions. This satisfies the stem's requirement for automatic analyst assignment without manual triage.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.